@daileyos/mcp-server
npm
v1.21.2
Published by @daileyos — no publish provenance and no public repository, so the publisher could not be verified and the source cannot be independently located.
Dailey OS MCP server for Claude Code and AI assistants
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 12 = 88. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −10 | capability blast radius (critical) — client exposure if the model is manipulated |
| −2 | publisher verification (unlinked) — no provenance/repo link, but the shipped source was fully read |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
This server (without client built-ins) exposes a complete data-exfiltration chain: dailey_build_logs → dailey_wordpress_migrate → dailey_db_exec. Untrusted input is ingested, private data is read, and it can be sent to an external sink via the agent composing the tools (→). Static analysis proves the primitive exists, not that a specific run will occur.
Fix: Remove one leg of the trifecta: isolate untrusted-input tools from secret-reading tools and from egress tools, or require human approval between them.
Location: flow dailey_build_logs → dailey_wordpress_migrate → dailey_db_exec
Tool "dailey_db_exec" appears to run shell commands or evaluate code (keyword "exec" in tool name). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool dailey_db_exec
Tool "dailey_exec" appears to run shell commands or evaluate code (keyword "exec" in tool name). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool dailey_exec
In the server's implementation (`dist/version.js:45`): A hardcoded outbound call to a fixed external host inside server code is a classic exfiltration/telemetry channel — especially paired with reads of local data. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: const res = await fetch('https://registry.npmjs.org/@daileyos%2Fmcp-server/latest', { signal: ctrl.sig
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/version.js
In the server's implementation (`src/version.ts:46`): A hardcoded outbound call to a fixed external host inside server code is a classic exfiltration/telemetry channel — especially paired with reads of local data. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: ; const res = await fetch('https://registry.npmjs.org/@daileyos%2Fmcp-server/latest', { signal: ctrl.signal,
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server src/version.ts
Tool "dailey_db_exec" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool dailey_db_exec
Tool "dailey_exec" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool dailey_exec
In a packaging/dev/install script (shipped, but not the server runtime) (`tests/dailey-images.test.mjs:17`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: rt { spawn } from 'node:child_process'; import { join, dirname } from 'node:path'; import { fileURLToPath } from 'node:u
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server tests/dailey-images.test.mjs
In a packaging/dev/install script (shipped, but not the server runtime) (`tests/environments.test.mjs:18`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: rt { spawn } from 'node:child_process'; import { join, dirname } from 'node:path'; import { fileURLToPath } from 'node:u
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server tests/environments.test.mjs
In a packaging/dev/install script (shipped, but not the server runtime) (`tests/mcp-protocol-smoke.mjs:9`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: rt { spawn } from 'node:child_process'; import path from 'node:path'; const binary = path.resolve(new URL('.', import.m
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server tests/mcp-protocol-smoke.mjs
In a packaging/dev/install script (shipped, but not the server runtime) (`tests/pack1-mcp-preflight.test.mjs:25`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: spawnSync } from 'node:child_process'; import { join, dirname } from 'node:path'; import { fileURLToPath } from 'node:u
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server tests/pack1-mcp-preflight.test.mjs
In a packaging/dev/install script (shipped, but not the server runtime) (`tests/pack6-smoke.mjs:14`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: rt { spawn } from 'node:child_process'; import path from 'node:path'; const here = path.resolve(new URL('.', import.met
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server tests/pack6-smoke.mjs
In a packaging/dev/install script (shipped, but not the server runtime) (`tests/wp-snapshot.test.mjs:19`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: rt { spawn } from 'node:child_process'; import { join, dirname } from 'node:path'; import { fileURLToPath } from 'node:u
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server tests/wp-snapshot.test.mjs
Each tool and what it can reach — statically extracted from the published source.
dailey_build_logsingests untrusted inputdailey_db_execruns code / shelldailey_execruns code / shelldailey_process_logsingests untrusted inputdailey_run_logsingests untrusted inputdailey_storage_infoingests untrusted inputdailey_storage_presign_downloadingests untrusted inputdailey_wordpress_migratereads sensitive datadailey_accountsno sensitive capabilitydailey_addon_cancelno sensitive capabilitydailey_addon_purchaseno sensitive capabilitydailey_addonsno sensitive capabilitydailey_admin_onboardno sensitive capabilitydailey_ai_enableno sensitive capabilitydailey_ai_infono sensitive capabilitydailey_analyze_repono sensitive capabilitydailey_app_logsno sensitive capabilitydailey_auth_enableno sensitive capabilitydailey_auth_statusno sensitive capabilitydailey_backupsno sensitive capabilitydailey_billingno sensitive capabilitydailey_billing_estimateno sensitive capabilitydailey_cli_suggest_importno sensitive capabilitydailey_compute_enableno sensitive capabilitydailey_create_projectno sensitive capabilitydailey_create_wordpressno sensitive capabilitydailey_creditsno sensitive capabilitydailey_credits_topupno sensitive capabilitydailey_db_importno sensitive capabilitydailey_db_infono sensitive capabilitydailey_db_migrate_cancelno sensitive capabilitydailey_db_migrate_confirmno sensitive capabilitydailey_db_migrate_startno sensitive capabilitydailey_db_migrate_statusno sensitive capabilitydailey_db_migrationsno sensitive capabilitydailey_db_recallno sensitive capabilitydailey_db_schemano sensitive capabilitydailey_db_tunnelno sensitive capabilitydailey_db_validateno sensitive capabilitydailey_delete_projectno sensitive capabilitydailey_deployno sensitive capabilitydailey_deploy_bundleno sensitive capabilitydailey_deploy_historyno sensitive capabilitydailey_deploy_multino sensitive capabilitydailey_deploy_rateno sensitive capabilitydailey_deploy_statusno sensitive capabilitydailey_diagnoseno sensitive capabilitydailey_domainsno sensitive capabilitydailey_email_disableno sensitive capabilitydailey_email_enableno sensitive capabilitydailey_email_statusno sensitive capabilitydailey_env_runtime_listno sensitive capabilitydailey_env_varsno sensitive capabilitydailey_environmentsno sensitive capabilitydailey_images_enableno sensitive capabilitydailey_images_generateno sensitive capabilitydailey_images_infono sensitive capabilitydailey_inspect_imageno sensitive capabilitydailey_list_projectsno sensitive capabilitydailey_marketplace_catalogno sensitive capabilitydailey_os_guideno sensitive capabilitydailey_pauseno sensitive capabilitydailey_platform_infono sensitive capabilitydailey_process_metricsno sensitive capabilitydailey_process_resourcesno sensitive capabilitydailey_process_restartno sensitive capabilitydailey_processesno sensitive capabilitydailey_project_credentialsno sensitive capabilitydailey_project_infono sensitive capabilitydailey_project_resourcesno sensitive capabilitydailey_project_servicesno sensitive capabilitydailey_project_transfer_applyno sensitive capabilitydailey_project_transfer_completeno sensitive capabilitydailey_project_transfer_planno sensitive capabilitydailey_project_transfer_rollbackno sensitive capabilitydailey_resource_configno sensitive capabilitydailey_resumeno sensitive capabilitydailey_reveal_credentialno sensitive capabilitydailey_rollbackno sensitive capabilitydailey_runno sensitive capabilitydailey_run_imageno sensitive capabilitydailey_scaleno sensitive capabilitydailey_service_linksno sensitive capabilitydailey_storage_enableno sensitive capabilitydailey_storage_list_objectsno sensitive capabilitydailey_storage_presign_uploadno sensitive capabilitydailey_supportno sensitive capabilitydailey_usageno sensitive capabilitydailey_usage_summaryno sensitive capabilitydailey_use_accountno sensitive capabilitydailey_whoamino sensitive capabilitydailey_wordpress_importno sensitive capabilitydailey_wp_clino sensitive capabilitydailey_wp_cloneno sensitive capabilitydailey_wp_filesno sensitive capabilitydailey_wp_listno sensitive capabilitydailey_wp_mediano sensitive capabilitydailey_wp_operation_statusno sensitive capabilitydailey_wp_restoreno sensitive capabilitydailey_wp_snapshotno sensitive capabilitydailey_wp_snapshotsno sensitive capabilitydailey_wp_targetno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.21.2 latest |
B 88/100 | 13 | 1.13.0 | 2026-09-07 |
v1.21.1 |
B 88/100 | 13 | 1.12.1 | 2026-08-09 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan @daileyos/mcp-server --online
Hotel booking MCP server — 300K+ properties, real confirmation numbers, loyalty programs. Builders monetize every booking via Stripe Connect. The first MCP server that completes real hotel reservations inside AI conversations.
Manage AdGuard Home through AI assistants
Read-only Azure DevOps for MCP clients using only your existing browser session — no PAT, no Azure CLI. Browse work items, pull requests, comments, attachments and Artifacts feeds across every project, repo and feed you can access.
MCP server for Adobe Experience Manager Assets integration development
Servidor MCP para el tiempo oficial de España (API pública OpenData de AEMET). Predicción, observación y avisos como herramientas MCP tipadas.
A standalone MCP stdio bridge for Affinity by Canva's local MCP SSE server.