Server data from the Official MCP Registry
Project Management Ai MCP server. Tools: decompose task, plan sprint, assess risks. Built by...
Project Management Ai MCP server. Tools: decompose task, plan sprint, assess risks. Built by...
This MCP server has a critical security vulnerability: it imports authentication middleware from a hardcoded filesystem path that is outside the package and controlled by the user's home directory. This allows attackers to inject malicious `auth_middleware.py` code that could intercept API keys, exfiltrate data, or bypass rate limiting. Additionally, the `api_key` parameter is passed to all tools as an optional string argument, making keys visible in tool invocation logs and MCP protocol messages. The server's permissions are appropriate for its purpose, but the authentication implementation is fundamentally broken. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.
7 files analyzed · 15 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-csoai-org-project-management-ai-mcp": {
"args": [
"-y",
"project-management-ai-mcp"
],
"command": "npx"
}
}
}Be the first to review this server!
by Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
by Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
by mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.