Is Wundervault MCP server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
Public scan report
scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it
2 medium
- Code scan23 source files scanned15/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 5 days ago15/15
- Maintainer identityregistry namespace matches repository owner7/10
Findings (2)
- mediumnpm install lifecycle script present
install.script - mediumnpm install lifecycle script present
install.scriptpackage.json: …Only": "npm run build && npm test", "postinstall": "chmod +x dist/agent.js dist/index.js 2…
Overall 66/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what Wundervault does
- Trusty SquireProvision, ship, and pay from your coding agent — keys and cards never leave the vault.not reviewedGrowingA
- IWEMarkdown knowledge base as agent memory. Runs against the notes directory it is started in.not reviewedEstablishedA
- mcptoonZero-dependency MCP client: one synced config for every agent, 581-token listings, not 71,929.not reviewedEstablishedA