Is Loki Mode MCP server safe?
Yes, with the usual care.
Safe to use. Minor gaps such as a missing repository or slower maintenance.
No critical or high findings in the latest scan.
Public scan report
scanner v0.1.9 · 2026-09-19 · same rubric, same numbers if you re-run it
2 medium
- Code scan482 source files scanned15/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 4 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (2)
- mediumeval / new Function used
exec.evalautonomy/run.sh: … # v7.5.8: Strict whitelist before eval (mirrors app-runner.sh # …
- mediumsubprocess with shell=True
exec.shell-trueweb-app/server.py: … # Start backend process (uses shell=True because command contains 'cd ...') …
Overall 77/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what Loki Mode does
- ReleasesAn agent-friendly API for product changelogs. A unified registry via CLI, API, or MCP.not reviewedGrowingA
AutoID Product Catalog & SupportRead-only AutoID Romania MCP for product search, live stock/prices, specs, and technical support.not reviewedGrowingA- Cra Annex Ii Docs Lint19 rules over the user documentation that ships with your product: support-period end date, vulnerabnot reviewedNewA