IBM Cloud CLI MCP server
Unverified package source
We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-expertvagabond-ibmcloud": {
"args": [
"-y",
"ibmcloud-mcp-server"
],
"command": "npx"
}
}
}The MCP server provides comprehensive IBM Cloud CLI access with 80+ tools but has serious security vulnerabilities. While it appropriately requires IBM Cloud authentication, it accepts API keys as plain text parameters, lacks input sanitization, and executes shell commands with user-controlled input without proper validation. Supply chain analysis found 2 known vulnerabilities in dependencies (0 critical, 2 high severity). Package verification found 1 issue (1 critical, 0 high severity).
Scanned 3 files · 8 findings
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Be the first to review this server!