Self-hostable study dashboard with a built-in MCP server, so that your Claude/ChatGPT subscription becomes x10 more effective for your semester
- capability exposureinferred+28
- trust mitigatorsmixed−3
inferredmixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 8m ago · see ecosystem CVEs →
- A · 0 → B · 25
No known CVEs for this server.
No tool-safety findings — heuristic detectors run on the compute-risk cadence; a finding appears when a tool trips a rule.
analyzed commit 4eab7ba · analyzer v17 · 2d ago
danger signals3
- suspicious endpointapi.telegram.orgOpenStudy-dev-OpenStudy-4eab7ba/app/mcp_tools.py:1129
f"https://api.telegram.org/bot{token}/sendMessage", - suspicious endpointapi.telegram.orgOpenStudy-dev-OpenStudy-4eab7ba/app/routers/settings.py:90
f"https://api.telegram.org/bot{sec.telegram_bot_token}/sendMessage", - suspicious endpointapi.telegram.orgOpenStudy-dev-OpenStudy-4eab7ba/app/services/telegram.py:30
f"https://api.telegram.org/bot{token}/sendMessage",
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of OpenStudy-dev.