Ascii Art Ai MCP Server by MEOK AI Labs
This ASCII art MCP server contains multiple security concerns that warrant caution. The most critical issue is an unauthenticated network call to `proofof.ai/verify` hardcoded in the server, which transmits user API keys over the network for server-side metering without explicit user consent or documentation of this behavior in the main tool docstrings. The authentication system relies on fail-open behavior that silently allows all calls if the remote service is unreachable, creating a denial-of-service vulnerability. Additionally, environment variable access patterns and monetization integration are not transparently disclosed to end users in tool documentation. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.
7 files analyzed · 15 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-csoai-org-ascii-art-ai-mcp": {
"args": [
"-y",
"ascii-art-ai-mcp"
],
"command": "npx"
}
}
}Be the first to review this server!
by Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
by Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
by Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.