Mmcp.market

Is Myc MCP server safe?

Probably. Read the findings first.

C66/100grade C

Use with care. Some checks failed or could not be verified.

Public scan report

scanner v0.1.8 · 2026-09-19 · same rubric, same numbers if you re-run it

3 medium
  • Code scan6 source files scanned10/25
  • Live reliabilityno gateway calls yet and no remote to proben/a
  • Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 0 days ago15/15
  • Maintainer identityregistry namespace matches repository owner6/10

Findings (3)

  • mediumnpm install lifecycle script presentinstall.script
  • mediumeval / new Function usedexec.eval
    dist/myc.js: …gs}) => { ${body} };`;ASM_CONSTS[start]=eval(func)}if("__start_em_asm"in moduleExport…
  • mediumnpm install lifecycle script presentinstall.script
    package.json: …": "bin/myc.js" }, "scripts": { "postinstall": "node bin/preflight.js" }, "engines…
Overall 66/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Other servers that do what Myc does

  • skillmem
    Skill memory for coding agents: learn, recall, reinforce, decay. Local SQLite, no API key.
    A
  • Memory Arbiter
    Local SQLite MCP memory: evidence-based recall, advisory conflict notices, authorized governance.
    A
  • KEPTA — Agent Memory
    Local memory for AI agents. One SQLite file on your machine — no cloud, no account.
    A

Myc reviews, tools and install