Runtime security guard for MCP servers, plus the package manager to install them. Search, install, audit, and guard across Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, and Gemini CLI.
- capability exposure inferred + 35
- recent drift inferred + 20
- tool safety inferred + 24
- trust mitigators mixed − 11
inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 9m ago · see ecosystem CVEs →
- C · 48 → D · 68
- C · 56 → C · 48
- B · 32 → C · 56
- C · 44 → B · 32
- C · 52 → C · 44
- D · 64 → C · 52
- C · 56 → D · 64
- A · 0 → C · 56
No known CVEs for this server.
- high dangerous code
committed secret: GitHub token, private key, GitLab token
- high hidden prompt content
1 file(s) with hidden prompt content: getmcpm-cli-cc2874b/CLAUDE.md (tag-smuggling): "smuggled ascii: "gbsct""
analyzed commit cc2874b · analyzer v33 · 3d ago
skills & prompt files 1
- hidden: agent-rules: tag-smuggling getmcpm-cli-cc2874b/CLAUDE.md :600
smuggled ascii: "gbsct"
danger signals8
- suspicious endpoint 93.184.216.34 getmcpm-cli-cc2874b/src/__tests__/registry/publish-client.test.ts :180
expect(() => validateRegistryUrl("https://93.184.216.34")).not.toThrow(); - suspicious endpoint 100.63.255.255 getmcpm-cli-cc2874b/src/__tests__/registry/publish-client.test.ts :181
expect(() => validateRegistryUrl("https://100.63.255.255")).not.toThrow(); - suspicious endpoint 100.128.0.1 getmcpm-cli-cc2874b/src/__tests__/registry/publish-client.test.ts :182
expect(() => validateRegistryUrl("https://100.128.0.1")).not.toThrow(); - suspicious endpoint 169.254.169.254 (cloud metadata) getmcpm-cli-cc2874b/src/registry/registry.test.ts :987
expect(() => new RegistryClient({ baseUrl: "https://169.254.169.254" })).toThrow( - committed secret GitHub token getmcpm-cli-cc2874b/src/guard/__tests__/fixtures/mcptox/attacks/credential-egress-github-pat.json :14
ghp_A1…(40 chars, redacted) - committed secret private key getmcpm-cli-cc2874b/src/guard/__tests__/fixtures/mcptox/attacks/credential-egress-private-key.json :14
PEM private key block (redacted) - committed secret GitHub token getmcpm-cli-cc2874b/src/guard/__tests__/patterns.test.ts :562
ghp_A1…(40 chars, redacted) - committed secret GitLab token getmcpm-cli-cc2874b/src/guard/__tests__/patterns.test.ts :640
glpat-…(53 chars, redacted)
- recent drift +20 capability drift →
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of getmcpm.