security
Security
Every MCP risk signal in one place — CVEs, tool safety, drift, naming, licenses. Heuristic: review signals, not verdicts.
45 CRITICAL
3626 HIGH
531 MEDIUM
1202 LOW
11 NONE
MCP-native tool-safety findings (tool poisoning, exfiltration combos, name shadowing, benign-dangerous tools, unconstrained schemas) from pure heuristics, newest-detected first; switch to the severity worklist to triage by impact — every row is a review signal with its evidence, never a verdict.
- exfiltration combo 861H 1159L
- dangerous code 1180H
- tool shadowing 233H 60M
- purpose mismatch 281M
- toxic flow (lethal trifecta) 185H
- tool poisoning 22H 15M
- hidden prompt content 36H
- loose schema 16M
- cross-server steering 2M
- HIGH hidden prompt content claude-all-config 1 file(s) with hidden prompt content: package/skills/telegram-alerts/SKILL.md (skill-exfil): "secret→sink: ### Via Telegram Bot API Direct"
- HIGH dangerous code @iola_adm/iola-cli dynamic exec: new Function()
- HIGH dangerous code @iola_adm/iola-cli env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (/tmp/obs-code-OHawcv/package/src/c
- HIGH dangerous code ecc-agentshield committed secret: OpenAI key, GitHub token
- HIGH dangerous code signetai suspicious bundled script in 1 file(s)
- HIGH toxic flow (lethal trifecta) agentmail-mcp lethal trifecta reachable across this server's tools: private-data access + untrusted-content ingestion + network exfil
- MEDIUM purpose mismatch agentmail-mcp · list_threads benign-looking name carries secrets
- MEDIUM purpose mismatch agentmail-mcp · list_inboxes benign-looking name carries secrets
- LOW exfiltration combo agentmail-mcp sensitive read and network capabilities split across this server's tools
- HIGH dangerous code tidewave dynamic exec: new Function()
- HIGH dangerous code @vpxa/aikit dynamic exec: new Function(), vm exec, eval()
- HIGH dangerous code brilliant-directories-mcp credential logged in 1 file(s)
- HIGH exfiltration combo @nexus2520/bitbucket-mcp-server · find_in_files single tool reads + sends: fs, net
- HIGH exfiltration combo @nexus2520/bitbucket-mcp-server · search_code single tool reads + sends: fs, net
- HIGH exfiltration combo @nexus2520/bitbucket-mcp-server · search_files single tool reads + sends: fs, net
- HIGH exfiltration combo @nexus2520/bitbucket-mcp-server · get_pull_request single tool reads + sends: fs, net
- HIGH dangerous code comfyui-mcp env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (/tmp/obs-code-ockRTX/package/plugi
- HIGH dangerous code aiwg suspicious bundled script in 1 file(s)
- HIGH hidden prompt content aiwg 10 file(s) with hidden prompt content: package/agentic/code/frameworks/media-curator/skills/cover-art-embedding/SKILL.md (skill-exfil), package/agentic/code/frameworks/media-curat…
- HIGH dangerous code aiwg env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (/tmp/obs-code-yGvQ7D/package/tools
- HIGH exfiltration combo harness-mcp-v2 · harness_schema single tool reads + sends: fs, net
- LOW exfiltration combo harness-mcp-v2 · harness_search single tool reads + sends: net, db
- HIGH exfiltration combo mcp-atlassian · upload_confluence_attachment single tool reads + sends: fs, net
- LOW exfiltration combo mcp-atlassian · search_confluence_pages single tool reads + sends: net, db
- HIGH dangerous code local-mcp env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (/tmp/obs-code-aTyMTA/package/setup