MCP Risk

Scan report

ai.korey/mcp

This page reports an automated security scan of ai.korey/mcp (remote), scanned 2026-07-28. It rates trust (provenance, transport, known vulnerabilities, instruction integrity) as grade C and capability risk (what the tools can do) separately at unknown. It does not certify the server is safe to connect; it reports what could be checked from outside.

remote, scanned 2026-07-28, tool surface via none

C 79/100 Capability risk: Unknown permalink

The grade rates trust: provenance, transport, known vulnerabilities and instruction integrity. Capability risk rates what the tools can do and is reported, not penalised – a server built to run shell commands is doing its job (Policy §2.4).

Automated checks

StatusCheckPolicyResult
PASS Listed on the official MCP registry §1.1
Listed on registry.modelcontextprotocol.io as ai.korey/mcp. 1 finding
  • Registry entry: ai.korey/mcp
WARN Source repository is public and maintained §1.2

No public source repository could be identified for this server.

INFO Published package is consistent and attested §1.3

No published package associated with this server (remote-only or non-npm/PyPI source).

UNVERIFIABLE Tool surface is inspectable and proportionate §2.1–§2.4

Tool surface could not be inspected (no reachable tools/list, no public package source). Per policy, unverifiability caps the overall grade.

PASS HTTPS-only endpoint §3.1
Endpoint uses HTTPS. 1 finding
  • Endpoint: https://mcp.korey.ai/mcp
PASS Authentication required §3.2
Server rejects anonymous requests and advertises its auth scheme. 1 finding
  • WWW-Authenticate: Bearer realm="Korey", resource_metadata="https://mcp.korey.ai/.well-known/oauth-protected-resource/mcp"
WARN OAuth protected-resource metadata published §3.3
No protected-resource metadata found - clients cannot discover the authorization server per spec. 1 finding
  • Checked: https://mcp.korey.ai/.well-known/oauth-protected-resource
INFO No known vulnerabilities (OSV.dev) §4.1

No package to query (remote-only server).

UNVERIFIABLE Server-supplied instructions free of poisoning indicators §5.1–§5.4

No server-supplied instructions or tool descriptions were obtainable to scan.

Verify manually - the scoring model can’t judge these for you

  • §2.3 - Is the tool surface no broader than the server’s stated purpose requires?
  • §3.4 - For stdio servers: which environment credentials does it read, and are they scoped rather than org-wide tokens?
  • §6.1 - Cross this server’s capabilities with your already-connected servers: any read-capability × send-capability pairs need explicit sign-off.
  • §6.2 - Run the connecting agent with sandboxing and egress controls sized to the combined tool surface, not just this server’s.

Methodology: MCP Server Security Policy. Checks and scoring weights are open source. Unfamiliar term? See the glossary.