@giovane.martins/localstack
npm
v1.1.5
Published by @giovane.martins — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
MCP server for LocalStack AWS services
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 7 = 93. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
This server (without client built-ins) exposes a complete data-exfiltration chain: s3_get_object → secretsmanager_get_secret → ses_send_email. Untrusted input is ingested, private data is read, and it can be sent to an external sink via the agent composing the tools (→). Static analysis proves the primitive exists, not that a specific run will occur.
Fix: Remove one leg of the trifecta: isolate untrusted-input tools from secret-reading tools and from egress tools, or require human approval between them.
Location: flow s3_get_object → secretsmanager_get_secret → ses_send_email
Tool "s3_put_object" can write, overwrite or delete files (keyword "put_object" in tool name). Verify it is scoped to a safe directory.
Fix: Constrain file operations to an explicit, non-sensitive root; reject path traversal.
Location: tool s3_put_object
Tool "s3_put_object" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool s3_put_object
Each tool and what it can reach — statically extracted from the published source.
s3_get_objectingests untrusted inputs3_put_objectwrites filessecretsmanager_get_secretreads sensitive datasecretsmanager_list_secretsreads sensitive datases_send_emailnetwork egresssqs_send_messagenetwork egressdynamodb_create_tableno sensitive capabilitydynamodb_delete_itemno sensitive capabilitydynamodb_delete_tableno sensitive capabilitydynamodb_describe_tableno sensitive capabilitydynamodb_get_itemno sensitive capabilitydynamodb_list_tablesno sensitive capabilitydynamodb_put_itemno sensitive capabilitydynamodb_queryno sensitive capabilitydynamodb_scanno sensitive capabilityeventbridge_create_busno sensitive capabilityeventbridge_delete_busno sensitive capabilityeventbridge_delete_ruleno sensitive capabilityeventbridge_describe_ruleno sensitive capabilityeventbridge_disable_ruleno sensitive capabilityeventbridge_enable_ruleno sensitive capabilityeventbridge_list_busesno sensitive capabilityeventbridge_list_rulesno sensitive capabilityeventbridge_list_targetsno sensitive capabilityeventbridge_put_eventsno sensitive capabilityeventbridge_put_ruleno sensitive capabilityeventbridge_put_targetsno sensitive capabilityeventbridge_remove_targetsno sensitive capabilitykinesis_create_streamno sensitive capabilitykinesis_delete_streamno sensitive capabilitykinesis_describe_streamno sensitive capabilitykinesis_get_recordsno sensitive capabilitykinesis_list_streamsno sensitive capabilitykinesis_put_recordno sensitive capabilitykinesis_put_recordsno sensitive capabilitylambda_create_functionno sensitive capabilitylambda_delete_functionno sensitive capabilitylambda_get_functionno sensitive capabilitylambda_invokeno sensitive capabilitylambda_list_functionsno sensitive capabilitys3_create_bucketno sensitive capabilitys3_delete_bucketno sensitive capabilitys3_delete_objectno sensitive capabilitys3_list_bucketsno sensitive capabilitys3_list_objectsno sensitive capabilitysecretsmanager_create_secretno sensitive capabilitysecretsmanager_delete_secretno sensitive capabilitysecretsmanager_describe_secretno sensitive capabilitysecretsmanager_restore_secretno sensitive capabilitysecretsmanager_update_secretno sensitive capabilityses_delete_identityno sensitive capabilityses_get_identity_verification_attributesno sensitive capabilityses_list_identitiesno sensitive capabilityses_verify_email_identityno sensitive capabilitysns_create_topicno sensitive capabilitysns_delete_topicno sensitive capabilitysns_list_subscriptions_by_topicno sensitive capabilitysns_list_topicsno sensitive capabilitysns_publishno sensitive capabilitysns_subscribeno sensitive capabilitysns_unsubscribeno sensitive capabilitysqs_create_queueno sensitive capabilitysqs_delete_messageno sensitive capabilitysqs_delete_queueno sensitive capabilitysqs_list_queuesno sensitive capabilitysqs_purge_queueno sensitive capabilitysqs_receive_messagesno sensitive capabilityssm_delete_parameterno sensitive capabilityssm_delete_parametersno sensitive capabilityssm_describe_parametersno sensitive capabilityssm_get_parameterno sensitive capabilityssm_get_parameters_by_pathno sensitive capabilityssm_put_parameterno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.1.5 latest |
A 93/100 | 3 | 1.13.0 | 2026-09-07 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan @giovane.martins/localstack --online
Independent packages implementing the same tool, scanned with the same engine. Compare all 2 side by side →
Hotel booking MCP server — 300K+ properties, real confirmation numbers, loyalty programs. Builders monetize every booking via Stripe Connect. The first MCP server that completes real hotel reservations inside AI conversations.
Manage AdGuard Home through AI assistants
Read-only Azure DevOps for MCP clients using only your existing browser session — no PAT, no Azure CLI. Browse work items, pull requests, comments, attachments and Artifacts feeds across every project, repo and feed you can access.
MCP server for Adobe Experience Manager Assets integration development
Servidor MCP para el tiempo oficial de España (API pública OpenData de AEMET). Predicción, observación y avisos como herramientas MCP tipadas.
A standalone MCP stdio bridge for Affinity by Canva's local MCP SSE server.