MCP Risk

Directory / server

ai.uselamina/lamina

This directory entry reports an automated security scan of ai.uselamina/lamina, scanned 2026-07-28. Trust grade D rates provenance, transport, known vulnerabilities and instruction integrity; capability risk is reported separately, not folded into the grade.

registry.modelcontextprotocol.io, scanned 2026-07-28, tool surface via remote-tools-list

D 61/100 permalink

Automated checks

StatusCheckPolicyResult
PASS Listed on the official MCP registry §1.1
Listed on registry.modelcontextprotocol.io as ai.uselamina/lamina. 1 finding
  • Registry entry: ai.uselamina/lamina
WARN Source repository is public and maintained §1.2

No public source repository could be identified for this server.

INFO Published package is consistent and attested §1.3

No published package associated with this server (remote-only or non-npm/PyPI source).

PASS Tool surface is inspectable and proportionate §2.1–§2.4
27 tool(s) enumerated. Capabilities detected: network-egress. Reported as capability risk (§2.4); whether each is essential to the server's stated purpose is §2.3 and remains a manual judgement. 3 findings
  • Tools exposed: 27
  • lamina_upload_asset: network-egress
  • Detected capabilities: network-egress
PASS HTTPS-only endpoint §3.1
Endpoint uses HTTPS. 1 finding
  • Endpoint: https://app.uselamina.ai/mcp/agent
FAIL Authentication required §3.2

Server answers anonymous requests (HTTP 200) while exposing non-trivial or unverifiable capabilities - fail per §3.2.

PASS OAuth protected-resource metadata published §3.3
Publishes /.well-known/oauth-protected-resource per the June 2025 authorization spec. 1 finding
  • Authorization server: https://app.uselamina.ai
INFO No known vulnerabilities (OSV.dev) §4.1

No package to query (remote-only server).

WARN Server-supplied instructions free of poisoning indicators §5.1–§5.4
6 suspicious indicator(s) found in server-supplied instructions, tool descriptions, or schemas. 6 findings
  • lamina_describe description: oversized: 2445 chars (limit 2048)
  • lamina_generate_image description: oversized: 2829 chars (limit 2048)
  • lamina_generate_video description: oversized: 3103 chars (limit 2048)
  • lamina_compose_video description: oversized: 2243 chars (limit 2048)
  • lamina_create description: oversized: 3388 chars (limit 2048)
  • lamina_generate_workflow description: oversized: 2461 chars (limit 2048)
What this grade covers
  • Provenance & supply-chain integrity (§1)
  • Tool surface & capability risk (§2)
  • Transport & authentication (§3)
  • Known CVEs via OSV.dev (§4)
  • Instruction/tool poisoning patterns (§5)

Limitations: pattern-based only (no semantic injection detection), static npm analysis (live server instructions not retrieved for package-only scans), single-server scope (no cross-server toxic flow analysis). See the full policy.

Methodology: MCP Server Security Policy. Unfamiliar term? See the glossary.