Real-time cost awareness for MCP agent workflows
Set these up before or after installing:
Environment variable: YOUR_API_KEY
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-dbsectrainer-mcp-cost-tracker-router": {
"env": {
"YOUR_API_KEY": "your-your-api-key-here"
},
"args": [
"-y",
"mcp-cost-tracker-router"
],
"command": "npx"
}
}
}This MCP cost tracker server has valid functionality for monitoring LLM costs but exhibits concerning security practices. Key issues include Slack webhook integration that could leak sensitive data, potential SQL injection vulnerabilities in database queries, and the use of arbitrary shell execution for notifications. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.
Scanned 3 files · 9 findings
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Be the first to review this server!