@otwa/sunucu-mcp
npm
v0.8.0
Published by @otwa — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
Model Context Protocol server for sunucu.com — manage servers, hosting, domains, billing, tickets and webhooks from Claude and other MCP-capable AI tools.
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 7 = 93. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Tools that read sensitive data ([sunucu_hosting_list_files, sunucu_hosting_read_file]) and tools that can send data out ([sunucu_hosting_set_cron, sunucu_list_webhooks, sunucu_get_webhook, sunucu_list_webhook_deliveries, sunucu_create_webhook, sunucu_update_webhook, sunucu_delete_webhook, sunucu_rotate_webhook_secret, sunucu_redeliver_webhook]) are exposed together. An agent can move private data to the sink.
Evidence: sources [sunucu_hosting_list_files, sunucu_hosting_read_file] → sinks [sunucu_hosting_set_cron, sunucu_list_webhooks, sunucu_get_webhook, sunucu_list_webhook_de
Fix: Keep secret-reading and egress capabilities on separate, separately-approved servers.
Location: flow sunucu_hosting_list_files → sunucu_hosting_set_cron
Tool "sunucu_hosting_set_cron" appears to run shell commands or evaluate code (parameter "command"). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool sunucu_hosting_set_cron
Tool "sunucu_create_webhook" takes a URL/host parameter "url" with no allowlist/pattern. An outbound-request tool with an unbounded destination enables SSRF and cloud-metadata access (e.g. 169.254.169.254).
Fix: Allowlist destinations or constrain the parameter; block private/link-local addresses server-side.
Location: tool sunucu_create_webhook · inputSchema.properties.url
Tool "sunucu_update_webhook" takes a URL/host parameter "url" with no allowlist/pattern. An outbound-request tool with an unbounded destination enables SSRF and cloud-metadata access (e.g. 169.254.169.254).
Fix: Allowlist destinations or constrain the parameter; block private/link-local addresses server-side.
Location: tool sunucu_update_webhook · inputSchema.properties.url
Tool "sunucu_hosting_write_file" can write, overwrite or delete files (keyword "write_file" in tool name). Verify it is scoped to a safe directory.
Fix: Constrain file operations to an explicit, non-sensitive root; reject path traversal.
Location: tool sunucu_hosting_write_file
Tool "sunucu_hosting_delete_file" can write, overwrite or delete files (keyword "delete_file" in tool name). Verify it is scoped to a safe directory.
Fix: Constrain file operations to an explicit, non-sensitive root; reject path traversal.
Location: tool sunucu_hosting_delete_file
Tool "sunucu_hosting_set_cron" takes a command-shaped parameter "command" with no enum/pattern constraint. Free-form, model- or attacker-controlled arguments reaching a shell is the command-injection precondition.
Fix: Constrain the parameter (enum/pattern), or build the command from a fixed template with escaped args.
Location: tool sunucu_hosting_set_cron · inputSchema.properties.command
Tool "sunucu_hosting_set_cron" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool sunucu_hosting_set_cron
Tool "sunucu_hosting_write_file" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool sunucu_hosting_write_file
Tool "sunucu_hosting_delete_file" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool sunucu_hosting_delete_file
Tool "sunucu_hosting_list_files" takes a path parameter "path" with no constraint. Without a canonicalize-and-contain check (not visible statically), this permits ../ traversal outside the intended root.
Fix: Resolve and verify the path stays within an allowed root; reject traversal sequences.
Location: tool sunucu_hosting_list_files · inputSchema.properties.path
Tool "sunucu_hosting_read_file" takes a path parameter "path" with no constraint. Without a canonicalize-and-contain check (not visible statically), this permits ../ traversal outside the intended root.
Fix: Resolve and verify the path stays within an allowed root; reject traversal sequences.
Location: tool sunucu_hosting_read_file · inputSchema.properties.path
Tool "sunucu_hosting_write_file" takes a path parameter "path" with no constraint. Without a canonicalize-and-contain check (not visible statically), this permits ../ traversal outside the intended root.
Fix: Resolve and verify the path stays within an allowed root; reject traversal sequences.
Location: tool sunucu_hosting_write_file · inputSchema.properties.path
Tool "sunucu_hosting_delete_file" takes a path parameter "path" with no constraint. Without a canonicalize-and-contain check (not visible statically), this permits ../ traversal outside the intended root.
Fix: Resolve and verify the path stays within an allowed root; reject traversal sequences.
Location: tool sunucu_hosting_delete_file · inputSchema.properties.path
Each tool and what it can reach — statically extracted from the published source.
sunucu_create_webhooknetwork egresssunucu_delete_webhooknetwork egresssunucu_get_webhooknetwork egresssunucu_hosting_delete_filewrites filessunucu_hosting_list_filesreads sensitive datasunucu_hosting_read_filereads sensitive datasunucu_hosting_set_cronruns code / shellsunucu_hosting_write_filewrites filessunucu_list_webhook_deliveriesnetwork egresssunucu_list_webhooksnetwork egresssunucu_redeliver_webhooknetwork egresssunucu_rotate_webhook_secretnetwork egresssunucu_update_webhooknetwork egresssunucu_add_mail_domainno sensitive capabilitysunucu_assign_pool_ipsno sensitive capabilitysunucu_change_planno sensitive capabilitysunucu_close_ticketno sensitive capabilitysunucu_create_aliasno sensitive capabilitysunucu_create_mailboxno sensitive capabilitysunucu_create_poolno sensitive capabilitysunucu_create_pool_serverno sensitive capabilitysunucu_create_snapshotno sensitive capabilitysunucu_delete_aliasno sensitive capabilitysunucu_delete_mail_domainno sensitive capabilitysunucu_delete_mailboxno sensitive capabilitysunucu_delete_server_ptrno sensitive capabilitysunucu_delete_snapshotno sensitive capabilitysunucu_get_accountno sensitive capabilitysunucu_get_domainno sensitive capabilitysunucu_get_hostingno sensitive capabilitysunucu_get_invoiceno sensitive capabilitysunucu_get_poolno sensitive capabilitysunucu_get_serverno sensitive capabilitysunucu_get_server_statsno sensitive capabilitysunucu_get_ticketno sensitive capabilitysunucu_get_walletno sensitive capabilitysunucu_hosting_add_databaseno sensitive capabilitysunucu_hosting_create_backupno sensitive capabilitysunucu_hosting_delete_backupno sensitive capabilitysunucu_hosting_get_cronno sensitive capabilitysunucu_hosting_list_backupsno sensitive capabilitysunucu_hosting_list_databasesno sensitive capabilitysunucu_hosting_logsno sensitive capabilitysunucu_hosting_remove_databaseno sensitive capabilitysunucu_hosting_restore_backupno sensitive capabilitysunucu_hosting_set_phpno sensitive capabilitysunucu_hosting_statsno sensitive capabilitysunucu_list_addonsno sensitive capabilitysunucu_list_domain_aliasesno sensitive capabilitysunucu_list_domain_mailboxesno sensitive capabilitysunucu_list_domainsno sensitive capabilitysunucu_list_hostingno sensitive capabilitysunucu_list_invoicesno sensitive capabilitysunucu_list_mail_domainsno sensitive capabilitysunucu_list_mailboxesno sensitive capabilitysunucu_list_plan_optionsno sensitive capabilitysunucu_list_pool_ipsno sensitive capabilitysunucu_list_pool_productsno sensitive capabilitysunucu_list_poolsno sensitive capabilitysunucu_list_server_ipsno sensitive capabilitysunucu_list_serversno sensitive capabilitysunucu_list_snapshotsno sensitive capabilitysunucu_list_ticketsno sensitive capabilitysunucu_list_wallet_transactionsno sensitive capabilitysunucu_mail_setupno sensitive capabilitysunucu_open_ticketno sensitive capabilitysunucu_power_serverno sensitive capabilitysunucu_purchase_addonno sensitive capabilitysunucu_quote_poolno sensitive capabilitysunucu_quote_pool_resizeno sensitive capabilitysunucu_reinstall_serverno sensitive capabilitysunucu_remove_addonno sensitive capabilitysunucu_remove_hosting_custom_domainno sensitive capabilitysunucu_reply_ticketno sensitive capabilitysunucu_reset_mailbox_passwordno sensitive capabilitysunucu_resize_poolno sensitive capabilitysunucu_revert_snapshotno sensitive capabilitysunucu_server_ssono sensitive capabilitysunucu_set_auto_rechargeno sensitive capabilitysunucu_set_hosting_custom_domainno sensitive capabilitysunucu_set_server_ptrno sensitive capabilitysunucu_terminate_poolno sensitive capabilitysunucu_terminate_serverno sensitive capabilitysunucu_update_domainno sensitive capabilitysunucu_verify_hosting_custom_domainno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v0.8.0 latest |
A 93/100 | 14 | 1.13.0 | 2026-09-07 |
v0.1.0 |
A 96/100 | 2 | 1.12.1 | 2026-08-20 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan @otwa/sunucu-mcp --online
Agent IP: MCP server with patents search tools
MCP server for searching the Agent Almanac — the public catalog of 9,000+ Model Context Protocol servers. Find, install, and discover MCP servers from inside Claude Desktop, Cursor, Continue, Zed, or any MCP-aware agent.
Search agents & MCP servers by capability, with daily-observed pricing, liveness and market data.
Verified merchants accepting agentic payments on Lightning/L402/BOLT12/USDT — search, verify, pay.
Airframe MCP Client - Connect agents to Airframe's product intelligence
Amazon product search demand over time, with growth for any keyword. Free key at trendsmcp.ai