Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 0 additions & 2 deletions npx/chrome-devtools-mcp/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -18,8 +18,6 @@ provenance:
repository_ref: "refs/heads/main"

security:
# Server requires a running Chrome instance to connect to - cannot complete startup in CI
insecure_ignore: true
allowed_issues:
- code: "AITech-1.1"
reason: "False positive - the evaluate_script tool allows JavaScript evaluation in browser pages which is core DevTools debugging functionality. The LLM analyzer flags this as prompt injection but it is legitimate browser automation capability, not malicious instruction manipulation. YARA did not flag this tool."
Expand Down
3 changes: 1 addition & 2 deletions npx/clarity-mcp-server/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -19,5 +19,4 @@ provenance:
repository_ref: "refs/heads/main"

security:
# Server requires --clarity_api_token to start - cannot be scanned in CI
insecure_ignore: true
allowed_issues: []
2 changes: 0 additions & 2 deletions npx/graphlit-mcp-server/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -18,8 +18,6 @@ provenance:
repository_ref: "refs/heads/main"

security:
# Server requires GRAPHLIT_JWT_SECRET and other credentials to start - cannot be scanned in CI
insecure_ignore: true
allowed_issues:
- code: "AITech-1.1"
reason: "False positive - extractText tool legitimately processes arbitrary user text through LLM for JSON data extraction. The text input is the data to be extracted from, not an attempt to manipulate LLM instructions. This is core functionality for structured data extraction from unstructured content."
Expand Down
2 changes: 0 additions & 2 deletions npx/heroku-mcp-server/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,8 +21,6 @@ provenance:
# YARA analyzer found no issues. LLM analyzer flagged tools that perform legitimate
# operations for the Heroku Platform MCP server by Salesforce/Heroku.
security:
# Server requires HEROKU_API_KEY to start - cannot be scanned in CI
insecure_ignore: true
allowed_issues:
- code: "AISubtech-12.1.2"
tool: "create_app"
Expand Down
20 changes: 18 additions & 2 deletions npx/perplexity-ask/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -18,5 +18,21 @@ provenance:
repository_ref: "refs/heads/main"

security:
# Server requires PERPLEXITY_API_KEY to start - cannot complete startup in CI
insecure_ignore: true
# Mock credentials allow tool discovery without a live service.
mock_env:
- name: PERPLEXITY_API_KEY
value: "mock-perplexity-api-key-for-scanning"
description: "Perplexity API key - mock value for security scanning"
allowed_issues:
- code: "AITech-8.2"
reason: |
Accepted data flow - YARA flags perplexity_ask, perplexity_research,
and perplexity_reason for sending conversation messages to an external
API. These tools explicitly provide Perplexity-hosted answers, research,
and reasoning. performAgentResponse maps caller-supplied message roles
and content into the request input and sends it to the authenticated
Perplexity Agent API (api.perplexity.ai by default, configurable via
PERPLEXITY_BASE_URL). This is the advertised service operation, not
hidden collection of local files or credentials. Users must only pass
conversation content they intend to share with Perplexity. Verified in
v1.3.0 (dist/server.js performAgentResponse and makeApiRequest).
2 changes: 0 additions & 2 deletions npx/phoenix-mcp/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,8 +21,6 @@ provenance:
# No security issues flagged by scanner for version 2.3.2
# Previous allowlist entries (AITech-8.2, AITech-9.1) removed as they are no longer flagged
security:
# Server requires PHOENIX_API_KEY and PHOENIX_BASE_URL to start - cannot be scanned in CI
insecure_ignore: true
allowed_issues:
- code: "AITech-1.1"
tool: "add-dataset-examples"
Expand Down
17 changes: 15 additions & 2 deletions npx/sentry-mcp-server/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -26,9 +26,22 @@ provenance:

# Security allowlist for known false positives
security:
# Server requires SENTRY_ACCESS_TOKEN to start - cannot be scanned in CI
insecure_ignore: true
# Mock credentials allow tool discovery without a live service.
mock_env:
- name: SENTRY_ACCESS_TOKEN
value: "mock-sentry-access-token-for-scanning"
description: "Sentry access token - mock value for security scanning"
allowed_issues:
- code: "AITech-1.1"
tool: "update_issue"
reason: |
False positive - YARA flags the update_issue description's instructions
to "ignore an issue" and "then ignore it again with the new rule" as
prompt injection. These describe Sentry's ignored issue status and
ignore-mode transitions, not instructions to disregard agent policies.
The handler validates the requested status and ignore options and calls
the authenticated Sentry issue-update API. Verified in v0.42.0
(dist/index.js update_issue and buildIgnoreUpdate).
- code: "AITech-9.1"
reason: |
YARA flags the search_docs tool with "command injection" (AISubtech-9.1.4) due to
Expand Down
10 changes: 8 additions & 2 deletions uvx/mcp-neo4j-aura-manager/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -19,5 +19,11 @@ provenance:

# Security configuration
security:
# Server requires Neo4j Aura API credentials to start - cannot be scanned in CI
insecure_ignore: true
# Mock credentials allow tool discovery without a live service.
mock_env:
- name: NEO4J_AURA_CLIENT_ID
value: "mock-aura-client-id-for-scanning"
description: "Neo4j Aura client ID - mock value for security scanning"
- name: NEO4J_AURA_CLIENT_SECRET
value: "mock-aura-client-secret-for-scanning"
description: "Neo4j Aura client secret - mock value for security scanning"
13 changes: 11 additions & 2 deletions uvx/mcp-neo4j-cypher/spec.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,15 @@ provenance:
repository_uri: "https://github.com/neo4j-contrib/mcp-neo4j"
repository_ref: "refs/tags/mcp-neo4j-cypher-v0.3.1"

# Security: Server requires NEO4J_URI, NEO4J_USERNAME, NEO4J_PASSWORD to start - cannot be scanned in CI
security:
insecure_ignore: true
# Mock credentials allow tool discovery without a live service.
mock_env:
- name: NEO4J_URI
value: "bolt://127.0.0.1:1"
description: "Unreachable Neo4j endpoint; tool discovery does not connect - mock value for security scanning"
- name: NEO4J_USERNAME
value: "neo4j"
description: "Neo4j username - mock value for security scanning"
- name: NEO4J_PASSWORD
value: "mock-neo4j-password-for-scanning"
description: "Neo4j password - mock value for security scanning"
Loading