High risk. Don't ship without significant remediation.
Scanned 5/1/2026, 9:24:31 AM·Cached result·Deep Scan·88 rules·View source ↗·How we decide ↗
AIVSS Score
High
Severity Breakdown
0
critical
2
high
3
medium
0
low
MCP Server Information
Findings
This package carries a D-grade security rating with two high-severity vulnerabilities spanning tool poisoning and prompt injection risks, plus three medium-severity server configuration issues that could expose it to misuse. The safety score of 79/100 and AIVSS rating of 7.1/10 indicate meaningful security gaps that warrant careful review before deployment, particularly around how it handles external inputs and manages server settings. Installation should be conditional on understanding and mitigating these specific attack vectors in your threat model.
AIPer-finding remediation generated by bedrock-claude-haiku-4-5 — 5 of 5 findings. Click any finding to read.
Scan Details
Done
Sign in to save scan history and re-scan automatically on new commits.
Building your own MCP server?
Same rules, same LLM judges, same grade. Private scans stay isolated to your account and never appear in the public registry. Required for code your team hasn’t shipped yet.
5 of 5 findings
5 findings