Is Particles MCP server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
What to know before installing
- highWhole environment serialized (possible credential exfil)
Public scan report
scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it
1 high
- Code scan272 source files scanned13/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 6 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year; website matches verified namespace10/10
Findings (1)
- highWhole environment serialized (possible credential exfil)
env.dumplinkedparticles-1.139.8/particles/ingest/importers/github.py: …e is public and forkable. git_env = os.environ.copy() git_env["GIT_ALLOW_PROTOCOL"] = "ht…
Overall 68/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what Particles does
- Roast My Design SystemAudit your Design System and serve your Agent the rules that keep AI-written UI on-system.not reviewedEstablishedA
- BomlyGive your coding agent the dependency graph it is about to change: scan, diff, explain, auditnot reviewedGrowingB
SomaCheck VibecheckSomaCheck returns proposition-specific Aligned or Unaligned plus model confidence.not reviewedGrowingA