Server data from the Official MCP Registry
Competitor intelligence for AI agents — SEO, traffic, social, Product Hunt, pricing, AI insights.
Competitor intelligence for AI agents — SEO, traffic, social, Product Hunt, pricing, AI insights.
Remote endpoints: streamable-http: https://www.analook.com/mcp
Analook is a competitor intelligence MCP server with reasonable architecture but several security concerns. The server requires API keys for multiple external services (TwitterAPI.io, Caravo, Apify, DataForSEO, ProductHunt) and makes extensive network calls. Key issues include: unauthenticated access to some tools (the README shows Bearer token auth is expected but code doesn't validate it), overly broad subprocess usage via npx/Caravo CLI with environment variable injection, missing input validation on URLs, and potential credential exposure in error messages. Permissions are appropriate for the stated purpose (competitor analysis), but code quality and error handling could be improved. Supply chain analysis found 13 known vulnerabilities in dependencies (0 critical, 6 high severity).
3 files analyzed · 23 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Unverified package source
We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.
Available as Local & Remote
This plugin can run on your machine or connect to a hosted endpoint. during install.
Be the first to review this server!
by Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
by Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
by Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.