REPOSITORY EVIDENCE / INDEXABLE REPORT

awslabs/mcp — MCP & Agent Security Evidence Report

MCP configuration, local command execution, CI/CD and dependency evidence were observed in this selected bounded review. Evidence observations are review signals, not a safe/unsafe verdict.

Is awslabs/mcp safe to run?

ShadowMCP does not issue a safe/unsafe verdict. This report records bounded evidence tied to a specific commit so reviewers can identify what deserves inspection before use.

Scan identity

Report schemashadowmcp.repo-evidence.v9
Scannershadowmcp.web-repo-scan.v22 semantics
Scan completed2026-09-23T07:56:00.000Z
Repository branchmain
Scanned commit2fec2904e21567090fa34412aa17a07d5c57edea
Indexation gateIndexable quality gate passed.

Evidence summary

Review priority
Priority review

This is a triage priority, not a repository risk rating.

The repository is explicitly an AWS MCP-server collection. The bounded review found MCP client configuration examples, subprocess-backed command execution in selected server utilities, GitHub automation, and Python dependency manifests across server packages.

Evidence categories

MCP configuration

Found

Configuration examples were observed; this does not establish how any user's environment is configured.

  • docusaurus/docs/installation.mdmcpServers configuration examples
  • src/finch-mcp-server/README.mdawslabs.finch-mcp-server configuration

Shell / command execution

Found

Selected implementation evidence was observed. This does not prove a vulnerability or unsafe operation.

  • src/ecs-mcp-server/.../utils/docker.pyPython subprocess.run used for Docker command flow
  • src/finch-mcp-server/.../utils/common.pysubprocess-based command execution helper

CI/CD automation

Found

Repository-level GitHub workflow automation is present in the selected scope.

  • .github/automation directory observed at repository root

Supply-chain / dependencies

Found

Python package dependency declarations are part of the multi-server repository.

  • DEVELOPER_GUIDE.mdpyproject.toml dependency workflow documented
  • src/amazon-mq-mcp-server/.../server.pyserver dependency declaration includes pydantic and boto3

Scope and limitations

Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1_PLUS_TARGETED_SEARCH. General recursive crawl: NO.

  • Public, selected and bounded repository evidence only.
  • FOUND means evidence observed, not risk or malicious behavior proven.
  • Search matches were reviewed against immutable commit 2fec2904e21567090fa34412aa17a07d5c57edea.
  • No repository clone or target-code execution.
  • No secret/token values are included.
  • No CVE or package-reputation lookup.
  • No numeric security score and no safe/unsafe verdict.

Repository context

Trust/community metadata is descriptive context only; it is not a security guarantee.

Repository age / activitycreated 2025-03-21 · 551 days old · last push 2026-09-22
Community signalsstars 9,724 · forks 1,770 · open issues 242
OwnershipOrganization · awslabs
LicenseApache-2.0
Repository statearchived NO · fork NO · default branch main

Continue the review