Back to Browse

Agent Identity Trust MCP Server

Developer ToolsUse Caution1.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Agent Identity Trust MCP Server by MEOK AI Labs

About

Agent Identity Trust MCP Server by MEOK AI Labs

Remote endpoints: streamable-http: https://api.meok.ai/v1/a2a/identity-trust

Security Report

1.2
Use Caution1.2Critical Risk

This MCP server contains multiple critical security vulnerabilities that substantially undermine trust and user safety. The most severe issue is an unsafe filesystem path traversal in the sys.path manipulation at module load, combined with reliance on an external shared authentication middleware that cannot be verified. Additionally, the server makes unauthenticated network calls to external metering endpoints (proofof.ai) without user consent or clear disclosure, creating a covert data exfiltration risk. The in-memory credential store is not persistent and offers no real security guarantees. While the code quality is moderate and the stated purpose (agent identity/DID management) is legitimate, the authentication bypass patterns, external phone-home calls, and unsafe path manipulation create an environment where this server could easily be abused or compromised. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

7 files analyzed · 16 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Reviews

No reviews yet

Be the first to review this server!