Hello maintainers,
I run LIFE FORGE, an MIT-licensed open-source security scanner for MCP tool definitions (github.com/zariffromlatif/life-forge). I recently scanned the most-installed servers in the ecosystem and want to share the findings on your reference implementations directly, before publishing summaries elsewhere.
What the scanner flagged on server-filesystem (probed live over stdio, definitions read off the wire):
- write_file performs a state-mutating operation with no confirmation, approval-token, or dry-run argument in its schema. Under indirect prompt injection - an attacker-controlled document instructing the agent to write a file - the only gate is the model's own judgment.
- All 14 tools declare string parameters without maxLength/pattern bounds, which admits arbitrary-length payloads into the agent's context.
On server-git: all 12 tools declare unbounded string parameters. No destructive-capability flags - the concern here is parameter bounding only.
These are design-level observations about the definitions, not claims of an exploitable vulnerability, and I recognize reference servers trade hardening for pedagogical clarity. But they are also the templates people copy, and the fix pattern (a confirm: true argument enforced server-side; maxLength on path/string parameters) costs a few lines per tool and would set the ecosystem standard.
Full report: results/MCP_ECOSYSTEM_SCAN.md in the repository above (per-server JSON evidence included; the ruleset is versioned and findings reproduce deterministically). If you believe any finding is wrong, I will re-run and publish a correction. I have not posted about your servers individually and will hold individual publicity until you have had a reasonable window.
Zarif Latif
Founder, Railo & LIFE FORGE
zarif.latif.biz@gmail.com
https://github.com/zariffromlatif/life-forge
Hello maintainers,
I run LIFE FORGE, an MIT-licensed open-source security scanner for MCP tool definitions (github.com/zariffromlatif/life-forge). I recently scanned the most-installed servers in the ecosystem and want to share the findings on your reference implementations directly, before publishing summaries elsewhere.
What the scanner flagged on server-filesystem (probed live over stdio, definitions read off the wire):
On server-git: all 12 tools declare unbounded string parameters. No destructive-capability flags - the concern here is parameter bounding only.
These are design-level observations about the definitions, not claims of an exploitable vulnerability, and I recognize reference servers trade hardening for pedagogical clarity. But they are also the templates people copy, and the fix pattern (a confirm: true argument enforced server-side; maxLength on path/string parameters) costs a few lines per tool and would set the ecosystem standard.
Full report: results/MCP_ECOSYSTEM_SCAN.md in the repository above (per-server JSON evidence included; the ruleset is versioned and findings reproduce deterministically). If you believe any finding is wrong, I will re-run and publish a correction. I have not posted about your servers individually and will hold individual publicity until you have had a reasonable window.
Zarif Latif
Founder, Railo & LIFE FORGE
zarif.latif.biz@gmail.com
https://github.com/zariffromlatif/life-forge