[mcp-inspector] MCP Inspector Report - 2026-05-25 #34749
Closed
Replies: 1 comment
-
|
This discussion was automatically closed because it expired on 2026-05-26T19:15:00.625Z.
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Summary
allowed: 7 serversInventory Table
Observations
🔐 Wildcard `allowed` — 7 servers
The following servers use
allowed: ["*"], granting access to all tools exposed by the server. This is a security consideration — if the upstream server adds new write/mutating tools, they become accessible without an explicit allowlist update.Recommendation: Add explicit allowlists to
agentdbandskillz— no justification is documented for the wildcard. The others have security decision comments.🔑 Secrets Summary — 10 servers
⚙️ Special Configurations
sentrux) to PATH. stdio MCP transport not supported by gateway. Used directly via bash.post-to-slack-channelcustom safe-output job. Message limit: 200 characters. Supports staged mode.serena.mdwithlanguages: ["go"]. Adds Go-specific analysis guidance.localhost. Cache-memory backed.jupyter+jupyter-mcp).Recommendations
agentdb.mdandskillz.md— wildcard with no documented justification.tavily.md(note says "pending follow-up").context7.md— usescontainer:key in frontmatter rather than standardimage:; verify compilation is correct.ast-grep,markitdown, andkreuzbergcontainer versions (latesttag) for supply-chain reproducibility.References:
/tmp/gh-aw/cache-memory/mcp-inspections/2026-05-25.jsonBeta Was this translation helpful? Give feedback.
All reactions