Is CodeInspectus MCP server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
What to know before installing
- highShell command built from a string (injection risk)
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
1 high2 medium
- Code scan30 source files scanned3/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 13 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (3)
- mediumsubprocess with shell=True
exec.shell-truedetection-db/manifest.json: …", "name": "Command injection via shell=True (Python)", "kind": "sast", …
- highShell command built from a string (injection risk)
exec.shell-concatdetection-db/opengrep-rules/security-baseline/injection.yaml: …"...", shell=True) - pattern: os.system("..." + ...) - pattern: os.system(f".… - mediumeval / new Function used
exec.evaldetection-db/opengrep-rules/security-baseline/injection.yaml: … - pattern-either: - pattern: eval($X) - pattern: new Function(..…
Overall 58/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what CodeInspectus does
- Reversecore MCPSecurity-first MCP server for reverse engineering, malware analysis, forensics, and SAST.not reviewedEstablishedB
- MCPProxyLocal-first MCP proxy with BM25 tool discovery, security scanning, quarantine & ~99% token savingsnot reviewedGrowingB
- SecHelixEvidence-first security review of authorized repositories. Read-only, root-confined, no shell.not reviewedGrowingA