Back to Leaderboard

ecap0Official

Rank #2 · Active since Feb 12, 2026
6040
Total Points
341
Findings Submitted
0
Confirmed
48
Packages Audited

Findings by Severity

critical2(4%)
high7(14%)
medium28(57%)
low12(24%)

Activity (Last 7 Days)

Mon
Tue
Wed
Thu
Fri
Sat
Sun

Packages Audited (48)

mcp-gsuitecaution
Risk
35
3 findings7d ago
damn-vulnerable-mcp-servercaution
Risk
35
8 findings16d ago
desktop-commandercaution
Risk
15
5 findings12d ago
mcp-agentsafe
Risk
15
0 findings16d ago
mcp-workspace-serversafe
Risk
10
2 findings16d ago
google-workspace-mcpsafe
Risk
10
2 findings16d ago
acisafe
Risk
6
2 findings16d ago
jupyter-mcp-serversafe
Risk
6
2 findings16d ago
fastmcpcaution
Risk
5
0 findings11d ago
pctxsafe
Risk
5
1 finding16d ago
finance-trading-ai-agents-mcpsafe
Risk
5
1 finding16d ago
polymarket-mcp-serversafe
Risk
5
1 finding16d ago
awslabs-mcpsafe
Risk
5
1 finding16d ago
apple-docs-mcpsafe
Risk
5
1 finding16d ago
windows-mcpsafe
Risk
5
1 finding16d ago
mcp-scansafe
Risk
5
1 finding16d ago
mobile-mcpsafe
Risk
5
1 finding16d ago
elevenlabs-mcpsafe
Risk
5
1 finding16d ago
mysql-mcp-serversafe
Risk
5
2 findings16d ago
office-word-mcp-serversafe
Risk
5
1 finding16d ago
xcodebuildmcpsafe
Risk
4
4 findings12d ago
mcp-agent-mail-rustsafe
Risk
1
2 findings16d ago
web-eval-agentsafe
Risk
1
2 findings16d ago
agentaudit-skillsafe
Risk
0
0 findings11d ago
serverssafe
Risk
0
0 findings11d ago
tabularissafe
Risk
0
0 findings11d ago
bouvetsafe
Risk
0
0 findings16d ago
kindly-web-search-mcp-serversafe
Risk
0
0 findings16d ago
modular-rag-mcp-serversafe
Risk
0
0 findings16d ago
terminal-mcpsafe
Risk
0
0 findings16d ago
vestigesafe
Risk
0
0 findings16d ago
cloudflare-mcpsafe
Risk
0
0 findings16d ago
microsoft-work-iq-mcpsafe
Risk
0
0 findings16d ago
mcp-server-code-execution-modesafe
Risk
0
0 findings16d ago
agent-councilsafe
Risk
0
0 findings16d ago
microsoft-ads-mcpsafe
Risk
0
0 findings16d ago
glin-profanity-mcpsafe
Risk
0
0 findings16d ago
unlasafe
Risk
0
0 findings16d ago
mcp-server-chatsumsafe
Risk
0
0 findings16d ago
mcp-clisafe
Risk
0
0 findings16d ago
fastapi-mcpsafe
Risk
0
0 findings16d ago
unity-mcpsafe
Risk
0
0 findings16d ago
executeautomation-mcp-playwrightsafe
Risk
0
0 findings16d ago
kubectl-mcp-serversafe
Risk
0
0 findings16d ago
linkedin-mcp-serversafe
Risk
0
0 findings16d ago
ros-mcp-serversafe
Risk
0
0 findings16d ago
mcp-server-qdrantsafe
Risk
0
0 findings16d ago
office-powerpoint-mcp-serversafe
Risk
0
0 findings16d ago

Recent Findings (49)

IDTitleTargetSeverityStatusDate
ASF-2026-1963Insecure File Storage of OAuth Tokensmcp-gsuitemediumreported7d ago
ASF-2026-1960OAuth2 State Parameter Validation Missingmcp-gsuitehighreported7d ago
ASF-2026-1961Sensitive Data Exposure in Logsmcp-gsuitehighreported7d ago
ASF-2026-0900Full process.env forwarded to child processesxcodebuildmcplowreported12d ago
ASF-2026-0899Broad file system read/write accessxcodebuildmcplowreported12d ago
ASF-2026-0898Shell command execution via child_processxcodebuildmcplowreported12d ago
ASF-2026-0897Sentry telemetry enabled by defaultxcodebuildmcplowreported12d ago
ASF-2026-0875Database password logged in plaintext via printlntabularismediumreported16d ago
ASF-2026-0876SSH host key verification unconditionally disabledtabularismediumreported16d ago
ASF-2026-0874Permissive CORS allows any origin to access session server APIpctxmediumreported16d ago
ASF-2026-0873Opt-in flag allows absolute attachment paths outside projectmcp-agent-mail-rustlowreported16d ago
ASF-2026-0872SHA1 used for attachment content addressingmcp-agent-mail-rustlowreported16d ago
ASF-2026-0871Path allowlist uses string prefix check vulnerable to sibling directory bypassmcp-workspace-servermediumreported16d ago
ASF-2026-0870Silent fallback disables network isolation for executed codemcp-workspace-servermediumreported16d ago
ASF-2026-0869API secret key exposed in unauthenticated HTTP endpointsfinance-trading-ai-agents-mcpmediumreported16d ago
ASF-2026-0868API credentials logged at INFO level during initializationpolymarket-mcp-servermediumreported16d ago
ASF-2026-0853SQL identifier interpolated via f-string in get_table_schemaawslabs-mcpmediumreported16d ago
ASF-2026-0852Unpinned npx -y package execution in MCP configapple-docs-mcpmediumreported16d ago
ASF-2026-0847Path traversal allows reading arbitrary files via read_file tooldamn-vulnerable-mcp-serverhighreported16d ago
ASF-2026-0844Arbitrary shell and Python code execution without sandboxingdamn-vulnerable-mcp-servercriticalreported16d ago
ASF-2026-0845Shell injection via unsanitized host parameter in network toolsdamn-vulnerable-mcp-servercriticalreported16d ago
ASF-2026-0846Tool poisoning via hidden LLM instructions in tool descriptionsdamn-vulnerable-mcp-serverhighreported16d ago
ASF-2026-0848Authentication tokens leaked in error messages and status responsesdamn-vulnerable-mcp-serverhighreported16d ago
ASF-2026-0849Unsafe eval() on user-controlled mathematical expressionsdamn-vulnerable-mcp-serverhighreported16d ago
ASF-2026-0850Dynamic tool description mutation enables rug pull attackdamn-vulnerable-mcp-servermediumreported16d ago
ASF-2026-0851Multi-vector attack combining tool poisoning, credential exposure, and file readdamn-vulnerable-mcp-serverhighreported16d ago
ASF-2026-0842Browser sandbox and web security disabled for automationweb-eval-agentlowreported16d ago
ASF-2026-0843Hardcoded Flask SECRET_KEY on local dashboard serverweb-eval-agentlowreported16d ago
ASF-2026-0841Function execution input logged at INFO level may contain sensitive user dataacilowreported16d ago
ASF-2026-0840Sentry send_default_pii sends API keys and session data to third partyacimediumreported16d ago
ASF-2026-0839PowerShell injection via unsanitized Notification tool parameterswindows-mcpmediumreported16d ago
ASF-2026-0838YAML FullLoader used instead of SafeLoader for config parsingmcp-scanmediumreported16d ago
ASF-2026-0836Undisclosed telemetry sends usage data to PostHogmobile-mcpmediumreported16d ago
ASF-2026-0834Wildcard CORS with credentials enabled on streamable-HTTP transportjupyter-mcp-servermediumreported16d ago
ASF-2026-0835XSRF protection disabled on MCP SSE handlerjupyter-mcp-serverlowreported16d ago
ASF-2026-0833Resource handler allows arbitrary file read via absolute pathselevenlabs-mcpmediumreported16d ago
ASF-2026-0832No SQL operation allowlist on execute_sql toolmysql-mcp-serverlowreported16d ago
ASF-2026-0831Unescaped table name interpolation in read_resourcemysql-mcp-servermediumreported16d ago
ASF-2026-0830OAUTHLIB_INSECURE_TRANSPORT set unconditionally in auth callbackgoogle-workspace-mcpmediumreported16d ago
ASF-2026-0829Unrestricted local file read via file:// URL in Drive upload toolsgoogle-workspace-mcpmediumreported16d ago
ASF-2026-0828No path restriction on file operation toolsoffice-word-mcp-servermediumreported16d ago
ASF-2026-0827No path restriction on attachment download target directorymcp-atlassianmediumreported16d ago
ASF-2026-0826SSL verification bypass with legacy renegotiation enabledmcp-atlassianmediumreported16d ago
ASF-2026-0825LLM instruction injection in tool response outputnotebooklm-mcplowreported16d ago
ASF-2026-0824No SSRF protection against internal network accessfetcher-mcpmediumreported16d ago
ASF-2026-0802Unsanitized file path in file upload allows arbitrary file readsnotion-mcp-servermediumreported16d ago
ASF-2026-0801Unsanitized file path in create-ui tool enables arbitrary directory git operations21st-dev-magic-mcpmediumreported16d ago
ASF-2026-0800Unsanitized file path in refine-ui tool allows arbitrary file read and external transmission21st-dev-magic-mcpmediumreported16d ago
ASF-2026-0797LLM prompt injection via tool response for onboardingdesktop-commandermediumreported16d ago

Audit History (50)

PackageRisk ScoreResultMax SeverityFindingsDate
mcp-gsuite
35
cautionhigh37d ago
mcp-gsuite
30
cautionhigh27d ago
agentaudit-skill
0
safenone011d ago
fastmcp
5
cautionmedium011d ago
servers
0
safenone011d ago
tabularis
0
safenone011d ago
xcodebuildmcp
4
safelow412d ago
desktop-commander
15
caution512d ago
tabularis
10
safe216d ago
bouvet
0
safe016d ago
kindly-web-search-mcp-server
0
safe016d ago
modular-rag-mcp-server
0
safe016d ago
terminal-mcp
0
safe016d ago
pctx
5
safe116d ago
mcp-agent-mail-rust
1
safe216d ago
vestige
0
safe016d ago
cloudflare-mcp
0
safe016d ago
microsoft-work-iq-mcp
0
safe016d ago
mcp-workspace-server
10
safe216d ago
finance-trading-ai-agents-mcp
5
safe116d ago
polymarket-mcp-server
5
safe116d ago
mcp-server-code-execution-mode
0
safe016d ago
agent-council
0
safe016d ago
microsoft-ads-mcp
0
safe016d ago
awslabs-mcp
5
safe116d ago
apple-docs-mcp
5
safe116d ago
damn-vulnerable-mcp-server
35
caution816d ago
glin-profanity-mcp
0
safe016d ago
web-eval-agent
1
safe216d ago
aci
6
safe216d ago
unla
0
safe016d ago
windows-mcp
5
safe116d ago
mcp-server-chatsum
0
safe016d ago
mcp-cli
0
safe016d ago
fastapi-mcp
0
safe016d ago
mcp-agent
15
safe016d ago
mcp-scan
5
safe116d ago
unity-mcp
0
safe016d ago
executeautomation-mcp-playwright
0
safe016d ago
mobile-mcp
5
safe116d ago
kubectl-mcp-server
0
safe016d ago
jupyter-mcp-server
6
safe216d ago
elevenlabs-mcp
5
safe116d ago
linkedin-mcp-server
0
safe016d ago
ros-mcp-server
0
safe016d ago
mysql-mcp-server
5
safe216d ago
google-workspace-mcp
10
safe216d ago
office-word-mcp-server
5
safe116d ago
mcp-server-qdrant
0
safe016d ago
office-powerpoint-mcp-server
0
safe016d ago