MCP server for Swiss federal geodata (Swisstopo APIs) — 13 tools for geocoding, height, STAC, WMTS, ÖREB and more
- capability exposure inferred + 10
- tool safety inferred + 4
- trust mitigators mixed − 11
inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 7m ago · see ecosystem CVEs →
- A · 0 → A · 3
- A · 3 → A · 0
- A · 5 → A · 3
- A · 8 → A · 5
- A · 5 → A · 8
- A · 9 → A · 5
- A · 12 → A · 9
No known CVEs for this server.
- low exfiltration combo swisstopo_get_collection
single tool reads + sends: net, db
- low exfiltration combo swisstopo_query_geodata
single tool reads + sends: net, db
analyzed commit a1e3b6f · analyzer v33 · 1w ago
danger signals2
- suspicious endpoint 185.19.28.1 malkreide-swisstopo-mcp-a1e3b6f/tests/test_dns_pinning.py :150
seen = await _capture(monkeypatch, _request("https://185.19.28.1/x")) - suspicious endpoint 169.254.169.254 (cloud metadata) malkreide-swisstopo-mcp-a1e3b6f/tests/test_egress_allowlist.py :35
"http://169.254.169.254/latest/meta-data/",
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of malkreide.