Is Gitworthy MCP server safe?
Yes, with the usual care.
Safe to use. Minor gaps such as a missing repository or slower maintenance.
No critical or high findings in the latest scan.
Public scan report
scanner v0.1.9 · 2026-09-24 · same rubric, same numbers if you re-run it
1 medium
- Code scan47 source files scanned20/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 34 days ago12/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (1)
- mediumeval / new Function used
exec.evaldist/cli/telemetry.js: … try { const importOptional = new Function('specifier', 'return import(specifier)')…
Overall 71/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what Gitworthy does
- GranethPre-flight check for AI coding agents: hallucinated packages + secrets, 6 ecosystems, no account.not reviewedGrowingA
- Phoenix Zero — L2 Health OraclePre-flight L2 health check using kernel-level eBPF telemetry. PASS/DEGRADED/FAIL verdict.not reviewedGrowingA
- NetOps Field NotesConfig drift, CIS/PCI checks, 802.1X diagnosis, certs inside configs, topology, change pre-flight.not reviewedNewA