[mcp-inspector] 🔍 MCP Inspector Report - 2026-09-21 #62445
Closed
Replies: 2 comments
|
🐾 Copilot smoke test rolled through your MCP Inspector discussion like a caveman discovering fire! Everything checked out shiny and green. Keep those wildcards tamed, friends. 🔥🤖 Warning Firewall blocked 7 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "update.googleapis.com"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
|
0 replies
|
This discussion was automatically closed because it expired on 2026-09-22T18:55:38.651Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Summary
.github/workflows/shared/mcp/)Inventory Table
Details
agentdb
shared/mcp/agentdb.md["*"]arxiv / brave / markitdown / notion / semgrep
# SECURITY:comment citing an upstream Critical/High CVE issue number and reactivation instructions. Good hygiene — no action needed until upstream ships a patched image.ast-grep
shared/mcp/ast-grep.mdast-grep-mcp@0.0.2)azure-devops
shared/mcp/azure-devops.mdADO_MCP_AUTH_TOKENorganizationimport input; network restricted to Azure DevOps domains.azure
shared/mcp/azure.mdmcr.microsoft.com/azure-sdk/azure-mcp, read-only mode)AZURE_TENANT_ID,AZURE_CLIENT_ID,AZURE_CLIENT_SECRETshared/azure-auth.md.datadog
shared/mcp/datadog.mdrequired: falseDD_API_KEY,DD_APPLICATION_KEY/DD_APP_KEYfallback,DD_SITEfallbackdeepwiki
shared/mcp/deepwiki.mdfabric-rti
shared/mcp/fabric-rti.mduvx microsoft-fabric-rti-mcp)grafana
shared/mcp/grafana.mdgrafana/mcp-grafana:1.1.0-alpine,--disable-write)GRAFANA_URL,GRAFANA_SERVICE_ACCOUNT_TOKENgraft
shared/mcp/graft.mdnpx ``@nanonets/graft`` ```@0```.8.0)jupyter
shared/mcp/jupyter.mdservices:(jupyter + jupyter-mcp sidecar containers)github.run_idas an ephemeral Jupyter token)kreuzberg
shared/mcp/kreuzberg.mdghcr.io/xberg-io/xberg), workspace mounted read-onlycache_clear,cache_warm) and feature-flagged (extract_structured) explicitly excluded with commentsmempalace
shared/mcp/mempalace.mdmempalace_add_drawer,mempalace_delete_drawer,mempalace_kg_add,mempalace_kg_invalidate)microsoftdocs
shared/mcp/microsoft-docs.mdhttps://learn.microsoft.com/api/mcp)ruflo
shared/mcp/ruflo.mdnpx ruflo@latest)sentrux
shared/mcp/sentrux.mdsentrux check,sentrux gate)sentry
shared/mcp/sentry.mdnpx ``@sentry/mcp-server`` ```@0```.33.0)SENTRY_OPENAI_API_KEYSENTRY_ACCESS_TOKEN,SENTRY_OPENAI_API_KEY(optional)serena-go
shared/mcp/serena-go.mdserena.mdwithlanguages: ["go"]and adds a Go setup stepserena
shared/mcp/serena.mdghcr.io/oraios/serena:1.7.0,--network host, workspace mounted read-write)allowed:field present — all server-exposed tools are available by default, unlike nearly every other config in this directory which defines an explicit allowlist or a documented wildcard rationale.rw(notrolike kreuzberg/skillz), consistent with its purpose as a code-editing LSP tool, but combined with an unrestricted tool list this is a wider blast radius than most peers. Consider adding an explicitallowed:list or a documented security rationale similar to azure.md/microsoft-docs.md/tavily.md.skillz
shared/mcp/skillz.md.github/skills/GH_TOKEN/GITHUB_TOKEN(usesgithub.token, not a repo secret)slack
shared/mcp/slack.mdpost-to-slack-channel), not an MCP serverSLACK_BOT_TOKENsvelte
shared/mcp/svelte.mdtavily
shared/mcp/tavily.mdTAVILY_API_KEYRecommendations
allowed:allowlist at all (unlike every other active server), giving it unrestricted tool access combined with a read-write workspace mount. Add an explicit tool allowlist or a documented security-decision comment justifying full access, matching the pattern used in azure.md, microsoft-docs.md, skillz.md, and tavily.md.mempalace_add_drawer,mempalace_delete_drawer,mempalace_kg_add,mempalace_kg_invalidate) without a documented rationale comment; add one or reassess whether delete/invalidate operations are needed by default.sentrux.mdandslack.mdlive undermcp/but are not MCP servers (a CLI tool install and a safe-output job respectively); this is a minor naming/organizational note, not a defect.All reactions