Mmcp.market

Is Gitworthy MCP server safe?

Yes, with the usual care.

B71/100grade B

Safe to use. Minor gaps such as a missing repository or slower maintenance.

No critical or high findings in the latest scan.

Public scan report

scanner v0.1.9 · 2026-09-24 · same rubric, same numbers if you re-run it

1 medium
  • Code scan47 source files scanned20/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitystatic API keys via environment variables6/15
  • Maintenancelast push 34 days ago12/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10

Findings (1)

  • mediumeval / new Function usedexec.eval
    dist/cli/telemetry.js: … try { const importOptional = new Function('specifier', 'return import(specifier)')…
Overall 71/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Other servers that do what Gitworthy does

  • Graneth
    Pre-flight check for AI coding agents: hallucinated packages + secrets, 6 ecosystems, no account.
    A
  • Phoenix Zero — L2 Health Oracle
    Pre-flight L2 health check using kernel-level eBPF telemetry. PASS/DEGRADED/FAIL verdict.
    A
  • NetOps Field Notes
    Config drift, CIS/PCI checks, 802.1X diagnosis, certs inside configs, topology, change pre-flight.
    A

Gitworthy reviews, tools and install