Scan identity
Evidence summary
The repository is explicitly an AWS MCP-server collection. The bounded review found MCP client configuration examples, subprocess-backed command execution in selected server utilities, GitHub automation, and Python dependency manifests across server packages.
Evidence categories
MCP configuration
FoundConfiguration examples were observed; this does not establish how any user's environment is configured.
docusaurus/docs/installation.mdmcpServers configuration examplessrc/finch-mcp-server/README.mdawslabs.finch-mcp-server configuration
Shell / command execution
FoundSelected implementation evidence was observed. This does not prove a vulnerability or unsafe operation.
src/ecs-mcp-server/.../utils/docker.pyPython subprocess.run used for Docker command flowsrc/finch-mcp-server/.../utils/common.pysubprocess-based command execution helper
CI/CD automation
FoundRepository-level GitHub workflow automation is present in the selected scope.
.github/automation directory observed at repository root
Supply-chain / dependencies
FoundPython package dependency declarations are part of the multi-server repository.
DEVELOPER_GUIDE.mdpyproject.toml dependency workflow documentedsrc/amazon-mq-mcp-server/.../server.pyserver dependency declaration includes pydantic and boto3
Scope and limitations
Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1_PLUS_TARGETED_SEARCH. General recursive crawl: NO.
- Public, selected and bounded repository evidence only.
- FOUND means evidence observed, not risk or malicious behavior proven.
- Search matches were reviewed against immutable commit 2fec2904e21567090fa34412aa17a07d5c57edea.
- No repository clone or target-code execution.
- No secret/token values are included.
- No CVE or package-reputation lookup.
- No numeric security score and no safe/unsafe verdict.
Repository context
Trust/community metadata is descriptive context only; it is not a security guarantee.