MCP server for Swiss energy data (SFOE/BFE) via GeoAdmin REST API — no API key required
This grade was produced by analyzer v32 , 1 version behind the one running now. Detectors added since have not been applied here, so it is not directly comparable with a server analyzed at the current version. A re-scan is queued.
- trust mitigators mixed − 11
These factors total -11, not 0: the score is bounded to 0–100 after they are summed, so this one is floored at 0. The factors are left as they were applied rather than rewritten to make the column add up.
mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 9m ago · see ecosystem CVEs →
- A · 3 → A · 0
No known CVEs for this server.
No tool-safety findings — heuristic detectors run on the compute-risk cadence; a finding appears when a tool trips a rule.
analyzed commit fa3bba2 · analyzer v32 · 1w ago
danger signals1
- suspicious endpoint 169.254.169.254 (cloud metadata) malkreide-swiss-energy-mcp-fa3bba2/tests/test_unit.py :138
assert_url_allowed("https://169.254.169.254/latest/meta-data")
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of malkreide.