← All scanned servers

Trust Card · Static snapshot

mcp-git B

79/100 · 1 findings (0 critical) · scope moderate · Ranked #27 of 53 scanned.

Scanned 2026-09-09 · engine v0.1.0 (8 regex rules, OWASP-mapped) · upstream modelcontextprotocol/servers @ d73f99e (2026-09-02)

Score breakdown

security 85
permissions 75
provenance 65
reliability 85
stability 75

Score constrained by 0 critical and 1 high-severity findings.

Fix first (1 critical/high)

SeverityRuleFindingRemediation
HIGHAT-SEC-005 (ASI02)Unrestricted Recursive File Deletion / Modification
tests/test_server.py:35
Evidence: shutil.rmtree(repo_path)
Enforce strict jail/root directories and require explicit human-in-the-loop confirmation before file deletions.

Permissions

Scope: moderate · Shell: disabled · Network egress: no · File deletion: enabled · Human approval: none

Provenance

License: MIT · Lockfile: no · Security policy: no · Signals: unverified origin

Independently scanned by the AgentTrust registry (not self-reported by the project). Static analysis only — no code executed, findings need human triage, counts may include test/example code. Static snapshot; re-scan before relying on it: npx @eulogik/agenttrust scan https://github.com/modelcontextprotocol/servers/tree/main/src/git. Scores move with every upstream commit; pages refresh weekly. How scoring works.