A minimal working MCP server over stdio in TypeScript and Python - stderr logging, error results, and real client configs.
Drift inferred · capture-to-capture
No drift recorded — single capability capture; advisories appear once its surface changes.
transport stdio counts 3 tools · 0 res
· 0 prompts
permission surface via code analysis
tools
-
get_service
-
list_services
-
search_services
prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed commit eb7d09c · analyzer v33 · 8h ago
danger signals1
- dynamic code execution __import__ sink duke5am-mcp-server-starter-eb7d09c/tests/e2e-python.py :8
args=[__import__("os").path.join(__import__("os").path.dirname(__import__("os").path.dirname(__import__("os").path.abspath(__file__))), "python", "server.py")],
evidence-backed
findings quoted directly from the published source artifact — not inferred
code files: 4
tool registrations 3
- list_services duke5am-mcp-server-starter-eb7d09c/typescript/src/server.ts :30
- get_service duke5am-mcp-server-starter-eb7d09c/typescript/src/server.ts :54
- search_services duke5am-mcp-server-starter-eb7d09c/typescript/src/server.ts :81
declared dependencies 1
- mcp@==2.2.0