MCP Risk

Directory / server

ai.meacheal/mrc-data

This directory entry reports an automated security scan of ai.meacheal/mrc-data, scanned 2026-07-28. Trust grade C rates provenance, transport, known vulnerabilities and instruction integrity; capability risk is reported separately, not folded into the grade.

registry.modelcontextprotocol.io, scanned 2026-07-28, tool surface via remote-tools-list

C 70/100 permalink

Automated checks

StatusCheckPolicyResult
PASS Listed on the official MCP registry §1.1
Listed on registry.modelcontextprotocol.io as ai.meacheal/mrc-data. 1 finding
  • Registry entry: ai.meacheal/mrc-data
WARN Source repository is public and maintained §1.2

No public source repository could be identified for this server.

INFO Published package is consistent and attested §1.3

No published package associated with this server (remote-only or non-npm/PyPI source).

PASS Tool surface is inspectable and proportionate §2.1–§2.4
20 tool(s) enumerated; no high-risk capability signals. 2 findings
  • Tools exposed: 20
  • Detected capabilities: none
PASS HTTPS-only endpoint §3.1
Endpoint uses HTTPS. 1 finding
  • Endpoint: https://api.meacheal.ai/mcp
UNVERIFIABLE Authentication required §3.2

Endpoint rejected the probe (HTTP 400); whether it requires authentication could not be determined.

WARN OAuth protected-resource metadata published §3.3
No protected-resource metadata found - clients cannot discover the authorization server per spec. 1 finding
  • Checked: https://api.meacheal.ai/.well-known/oauth-protected-resource
INFO No known vulnerabilities (OSV.dev) §4.1

No package to query (remote-only server).

WARN Server-supplied instructions free of poisoning indicators §5.1–§5.4
17 suspicious indicator(s) found in server-supplied instructions, tool descriptions, or schemas. 17 findings
  • search_suppliers description: oversized: 3547 chars (limit 2048)
  • get_supplier_detail description: oversized: 3208 chars (limit 2048)
  • search_fabrics description: oversized: 3259 chars (limit 2048)
  • get_fabric_detail description: oversized: 2440 chars (limit 2048)
  • search_clusters description: oversized: 2652 chars (limit 2048)
  • compare_clusters description: oversized: 2117 chars (limit 2048)
  • detect_discrepancy description: oversized: 2827 chars (limit 2048)
  • get_supplier_fabrics description: oversized: 2204 chars (limit 2048)
  • get_fabric_suppliers description: oversized: 2116 chars (limit 2048)
  • recommend_suppliers description: oversized: 2676 chars (limit 2048)
  • estimate_cost description: oversized: 2295 chars (limit 2048)
  • check_compliance description: oversized: 2674 chars (limit 2048)
  • find_alternatives description: oversized: 2977 chars (limit 2048)
  • compare_suppliers description: oversized: 2169 chars (limit 2048)
  • get_supplier_detail: imperative to the model: You MUST first
  • get_fabric_detail: imperative to the model: You MUST first
  • compare_clusters: imperative to the model: You MUST first

Score history

DateGradeScore
2026-07-28C70/100
2026-07-27C70/100
2026-07-26C70/100
2026-07-25C75/100
2026-07-13D64/100
What this grade covers
  • Provenance & supply-chain integrity (§1)
  • Tool surface & capability risk (§2)
  • Transport & authentication (§3)
  • Known CVEs via OSV.dev (§4)
  • Instruction/tool poisoning patterns (§5)

Limitations: pattern-based only (no semantic injection detection), static npm analysis (live server instructions not retrieved for package-only scans), single-server scope (no cross-server toxic flow analysis). See the full policy.

Methodology: MCP Server Security Policy. Unfamiliar term? See the glossary.