Is mcpm MCP server safe?
Yes, with the usual care.
Safe to use. Minor gaps such as a missing repository or slower maintenance.
No critical or high findings in the latest scan.
Public scan report
scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it
1 medium
- Code scan66 source files scanned20/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner7/10
Findings (1)
- mediumeval / new Function used
exec.evaldist/chunk-TOP22SML.js: …rlier // draft instead matched `new Function(`/IIFE syntax with NO call // ga…
Overall 83/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what mcpm does
- prompt-protectionScan prompts, tool definitions and model output for injection, and guard agent tool calls.not reviewedGrowingA
- Aletheia Runtime Safety & Scope Creep FilterDeterministic pre-execution filter that blocks known scope-creep and prompt-injection tool callsnot reviewedGrowingB
- HOL GuardLocal-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server.not reviewedEstablishedC