data-ai MCP Server
The open source security engine for AI agent and supply-chain trust.
Discovered via github-seeds:mcp-hot and last synced 3mo ago.
Install instructions not detected yet
Check the source repository for the latest setup steps.
Flag
Rules
`true`
Unpinned npx/uvx servers, hardcoded secrets, Docker cap-add, host networking, pip without hashes
Default
API keys (OpenAI, AWS, GCP, Stripe, ...), private keys, DB strings, HMAC secrets
`sarif`
No
Engine
`./`
Download-and-execute, reverse shells, sandbox escape, symlink attacks, privilege escalation
`info`
shell=True, eval, subprocess, child_process, PowerShell
Aguara
_(none)_
_(latest)_
RTL override, bidi, homoglyphs, zero-width sequences, normalization bypass
Effect
Credential file reads, .pth executable code, bulk env collection, K8s secrets access, systemd persistence, archive+POST exfil, Session-Network endpoints
`packages.lock.json`, `*.csproj`/`*.fsproj`/`*.vbproj`
`Gemfile.lock`
`site-packages`, `.pth`, pip/uv/npx caches
Engine
Partial
Evidence read
`pom.xml`, Gradle lockfiles
Examples
`go.sum`, `go.mod`
Yes
npm, pnpm, PyPI, Go, Rust, PHP, Ruby, Java, .NET
`composer.lock`
Download-and-execute, reverse shells, sandbox escape, symlink attacks, privilege escalation, OIDC token vars, runner-pivot memory, Claude Code persistence path
`node_modules`, pnpm `.pnpm` store, `pnpm-lock.yaml`, `package-lock.json`, `yarn.lock` (classic v1 + Berry v2+), `bun.lock`
Detector
Severity
`defaultMode: "bypassPermissions"` shipped in the repo
`apiKeyHelper` / `awsAuthRefresh` pointing at a repo-relative script
`--format terminal` (default): color, severity dashboard, top-files chart
`defaultMode: "acceptEdits"` / `"auto"` shipped in the repo
`onlyBuiltDependencies` and friends
a hook command piping a network fetch into a shell (`curl \
`--format json`: machine processing, API integration
`--format sarif`: GitHub Code Scanning, IDE / SAST dashboards
`--format markdown`: GitHub Actions job summaries, PR comments
`package.json` JSON
JavaScript single-pass
Python install-hook scanner
Cargo build-script scanner
Goldmark AST + JSON/YAML
SHA256 change tracking