@msfeldstein/mcp-test-servers
npm
v1.1.72
Published by @msfeldstein — no publish provenance and no public repository, so the publisher could not be verified and the source cannot be independently located.
A collection of MCP test servers including working servers (ping, resource, combined, env-echo) and test failure cases (broken-tool, crash-on-startup)
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 8 = 92. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
| −2 | publisher verification (unlinked) — no provenance/repo link, but the shipped source was fully read |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
In the server's implementation (`src/shell-exec-server.js:5`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: t { exec, spawn } from 'child_process'; import { promisify } from 'util'; const execAsync = promisify(exec); const ser
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server src/shell-exec-server.js
In the server's implementation (`src/cli.js:34`): Loading a module chosen at runtime (from a variable) can pull in and run attacker-influenced code paths. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: cute the Node.js server import(serverConfig.file);
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server src/cli.js
In a packaging/dev/install script (shipped, but not the server runtime) (`scripts/oauth-debug-setup.js:3`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: import { spawn } from 'child_process'; import { readFileSync } from 'fs'; import { join, dirname } from 'path'; import
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server scripts/oauth-debug-setup.js
Each tool and what it can reach — statically extracted from the published source.
execute-sqlreads sensitive dataaddno sensitive capabilityall_types_toolno sensitive capabilityanalyze_textno sensitive capabilityanother-missing-typeno sensitive capabilityask-favorite-colorno sensitive capabilityask-nameno sensitive capabilityask-programming-languageno sensitive capabilitybad-paramno sensitive capabilitybug-statusno sensitive capabilitycrashno sensitive capabilitydebug-oauthno sensitive capabilitydelayedPingno sensitive capabilitydelete-projectno sensitive capabilitydivideno sensitive capabilitydynamic_featureno sensitive capabilityechono sensitive capabilityecho_env_varno sensitive capabilityecho_mcp_rootsno sensitive capabilityecho_structuredno sensitive capabilityecho_with_paramsno sensitive capabilityenv_echono sensitive capabilityfactorialno sensitive capabilityfizzbuzzno sensitive capabilityformat_datano sensitive capabilitygenerate_big_responseno sensitive capabilitygenerate_imageno sensitive capabilityget_mixed_resourcesno sensitive capabilityget-headersno sensitive capabilityget-infono sensitive capabilityget-resource-listno sensitive capabilityget-session-infono sensitive capabilityget-timeno sensitive capabilitylog-to-stderrno sensitive capabilitylong_running_progressno sensitive capabilitylong-running-pingno sensitive capabilitylong-running-taskno sensitive capabilitylong-running-task-with-messageno sensitive capabilitylong-running-task-with-no-totalno sensitive capabilitymakeRequestno sensitive capabilitymany-resources-toolno sensitive capabilitymissing-type-toolno sensitive capabilitymulti-step-elicitationno sensitive capabilitymultiplyno sensitive capabilitynumber-paramno sensitive capabilityoptionalToolno sensitive capabilityparse_bugsnag_error_urlno sensitive capabilitypingno sensitive capabilitypowerno sensitive capabilityroot-echono sensitive capabilitysafe_header_infono sensitive capabilitysearch_documentationno sensitive capabilitysimple_pingno sensitive capabilitysqrtno sensitive capabilitystart-notification-streamno sensitive capabilitystatusno sensitive capabilitysubtractno sensitive capabilityterminate-sessionno sensitive capabilitytest_all_elicitationsno sensitive capabilitytest-anyof-integerno sensitive capabilitytest-both-paramsno sensitive capabilitytest-edge-casesno sensitive capabilitytest-simple-integerno sensitive capabilitytoggle_dynamic_toolno sensitive capabilitytoggleToolno sensitive capabilitytoken-infono sensitive capabilitywhoamino sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.1.72 latest |
A 92/100 | 3 | 1.13.0 | 2026-09-07 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan @msfeldstein/mcp-test-servers --online
Apify MCP Server
Model Context Protocol (MCP) Server for the *@inkeep/agents-mcp* API.
Medicare spending, chronic conditions, hospital quality, readmissions, and enrollment
Public read-only MCP for products, frameworks, guides, methodology, and blog metadata.
Community-maintained MCP server for Atlassian Confluence Data Center. Not affiliated with Atlassian.
MCP server for Contentful Content Management API integration