MCP Risk

Directory / server

ai.rapay/mcp-server

This directory entry reports an automated security scan of ai.rapay/mcp-server, scanned 2026-07-28. Trust grade C rates provenance, transport, known vulnerabilities and instruction integrity; capability risk is reported separately, not folded into the grade.

registry.modelcontextprotocol.io, scanned 2026-07-28, tool surface via package-source

C 68/100 permalink

Automated checks

StatusCheckPolicyResult
PASS Listed on the official MCP registry §1.1
Listed on registry.modelcontextprotocol.io as ai.rapay/mcp-server. 1 finding
  • Registry entry: ai.rapay/mcp-server
FAIL Source repository is public and maintained §1.2

Claimed source repository does not exist (or is private).

FAIL Published package is consistent and attested §1.3
Latest version is deprecated by its own maintainer. 6 findings
  • Package: @rapay/mcp-server@1.3.2
  • Ecosystem: npm
  • Age: 190 days
  • Weekly downloads: 34
  • Repo field matches source repo: true
  • Build-provenance attestation: absent
PASS Tool surface is inspectable and proportionate §2.1–§2.4
Package source scanned. Capabilities detected: filesystem, network-egress. Reported as capability risk (§2.4); whether each is essential to the server's stated purpose is §2.3 and remains a manual judgement. 4 findings
  • filesystem (filesystem write/delete): dist/audit.js
  • filesystem (fs module import): dist/audit.js
  • network-egress (outbound network calls): dist/version-check.js
  • Detected capabilities: filesystem, network-egress
INFO Transport & authentication §3

Local (stdio) server: runs with host-process privileges by design. Transport checks apply to remote servers; scrutiny shifts to §1/§2.

PASS No known vulnerabilities (OSV.dev) §4.1

No advisories on record for @rapay/mcp-server @1.3.2 (npm).

PASS Server-supplied instructions free of poisoning indicators §5.1–§5.4

No poisoning indicators found across 13 server-supplied text item(s).

What this grade covers
  • Provenance & supply-chain integrity (§1)
  • Tool surface & capability risk (§2)
  • Transport & authentication (§3)
  • Known CVEs via OSV.dev (§4)
  • Instruction/tool poisoning patterns (§5)

Limitations: pattern-based only (no semantic injection detection), static npm analysis (live server instructions not retrieved for package-only scans), single-server scope (no cross-server toxic flow analysis). See the full policy.

Methodology: MCP Server Security Policy. Unfamiliar term? See the glossary.