Skip to content

Enable security scans for nine MCP servers - #1094

Merged
danbarr merged 1 commit into
mainfrom
enable-mcp-security-scans
Oct 9, 2026
Merged

danbarr merged 1 commit into
mainfrom
enable-mcp-security-scans

Conversation

@danbarr

@danbarr danbarr commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Nine MCP servers currently bypass security scanning even though they can expose tools without live service credentials. Remove their insecure_ignore settings and add scanner-only mock_env credentials for Sentry, Perplexity, Neo4j Aura Manager, and Neo4j Cypher. Heroku, Phoenix, Clarity, Graphlit, and Chrome DevTools expose tools without credentials.

Triage the newly exposed HIGH findings with documented allowlist reasons:

  • Sentry update_issue: false positive from instructions for the ignored issue status and ignore-mode transitions.
  • Perplexity perplexity_ask, perplexity_research, and perplexity_reason: expected transmission of caller-supplied conversation messages to the authenticated Perplexity Agent API.

The existing result processor matches allowances by taxonomy code across each server; it does not enforce tool-level scope. Bright Data is handled separately in #1086. Stripe, Okta, and Neo4j Memory retain their startup bypasses.

Validation: all nine local YARA scans and repository result-processing checks passed with scanner 4.8.2, covering 192 tools with zero blocking findings. Sentry's SDK override was preserved during scanning. git diff --check passed. LLM analysis and container builds were not run.

CI validation: MCP security scans passed for all nine servers. Three container builds fail on pre-existing Grype vulnerability findings, unrelated to these scan-configuration changes.

Replace startup scan bypasses with mock credentials where needed.
Document Sentry's issue-status false positive and Perplexity's
expected API data flow in the security allowlists.

Signed-off-by: Dan Barr <6922515+danbarr@users.noreply.github.com>
@toolhive-release-app

Copy link
Copy Markdown
Contributor

🔒 MCP Security Scan Results

✅ chrome-devtools-mcp

  • Status: Passed
  • Tools scanned: 30
  • Result: No security issues detected

✅ clarity-mcp-server

  • Status: Passed
  • Tools scanned: 3
  • Result: No security issues detected

✅ graphlit-mcp-server

  • Status: Passed
  • Tools scanned: 71
  • Result: No security issues detected

✅ heroku-mcp-server

  • Status: Passed
  • Tools scanned: 33
  • Result: No security issues detected

✅ mcp-neo4j-aura-manager

  • Status: Passed
  • Tools scanned: 12
  • Result: No security issues detected

✅ mcp-neo4j-cypher

  • Status: Passed
  • Tools scanned: 3
  • Result: No security issues detected

✅ perplexity-ask

  • Status: Passed
  • Tools scanned: 4
  • Result: No security issues detected

✅ phoenix-mcp

  • Status: Passed
  • Tools scanned: 27
  • Result: No security issues detected

✅ sentry-mcp-server

  • Status: Passed
  • Tools scanned: 9
  • Result: No security issues detected

Summary: Scanned 9 MCP server(s), all passed security checks. ✅

@toolhive-release-app

Copy link
Copy Markdown
Contributor

Dependency Override Check

npm overrides are exact, tree-global pins. This resolves each changed spec without its overrides and compares. A pin below the highest version otherwise present silently downgrades that copy. Informational only; the Grype scan is the hard gate.

✅ sentry-mcp-server

  • @modelcontextprotocol/sdk pinned 1.31.0; without override: 1.30.0.

@danbarr
danbarr merged commit 6fb0bd8 into main Oct 9, 2026
36 of 39 checks passed
@danbarr
danbarr deleted the enable-mcp-security-scans branch October 9, 2026 16:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants