← All scanned servers

Trust Card · Static snapshot

PrefectHQ__prefect-mcp-server B

83/100 · 1 findings (1 critical) · scope minimal · Ranked #24 of 53 scanned.

Scanned 2026-09-09 · engine v0.1.0 (8 regex rules, OWASP-mapped) · upstream PrefectHQ/prefect-mcp-server @ 390e38c (2026-09-08)

Score breakdown

security 75
permissions 100
provenance 75
reliability 85
stability 75

Score constrained by 1 critical and 0 high-severity findings.

Fix first (1 critical/high)

SeverityRuleFindingRemediation
CRITICALAT-SEC-002 (LLM02)Hardcoded Credential or API Secret
evals/rate_limits/conftest.py:24
Evidence: CLOUD_OAUTH_TOKEN_KEY = "notArealACCESStokenKEY"
Move credentials to secure environment variables or a key vault. Never commit API keys.

Permissions

Scope: minimal · Shell: disabled · Network egress: no · File deletion: none · Human approval: none

Provenance

License: MIT · Lockfile: no · Security policy: yes · Signals: unverified origin

Independently scanned by the AgentTrust registry (not self-reported by the project). Static analysis only — no code executed, findings need human triage, counts may include test/example code. Static snapshot; re-scan before relying on it: npx @eulogik/agenttrust scan https://github.com/PrefectHQ/prefect-mcp-server. Scores move with every upstream commit; pages refresh weekly. How scoring works.