MCP server that dispatches physical-world tasks to humans through a unified API
This grade was produced by analyzer v32 , 1 version behind the one running now. Detectors added since have not been applied here, so it is not directly comparable with a server analyzed at the current version. A re-scan is queued.
- capability exposure inferred + 6
- trust mitigators mixed − 8
These factors total -2, not 0: the score is bounded to 0–100 after they are summed, so this one is floored at 0. The factors are left as they were applied rather than rewritten to make the column add up.
inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 7m ago · see ecosystem CVEs →
No known CVEs for this server.
- low dangerous code
env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
analyzed commit d8d9f83 · analyzer v32 · 1d ago
danger signals1
- suspicious endpoint 169.254.169.254 (cloud metadata) zyntarasystems-human-dispatch-mcp-d8d9f83/src/services/security/url-guard.test.ts :21
"https://169.254.169.254/",
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of zyntarasystems.