REPOSITORY EVIDENCE / INDEXABLE REPORT

modelcontextprotocol/servers — MCP & Agent Security Evidence Report

MCP configuration, process-execution test evidence, CI/CD and dependency evidence were observed in this bounded review of the official reference-server repository. Evidence observations are review signals, not a safe/unsafe verdict.

Is modelcontextprotocol/servers safe to run?

ShadowMCP does not issue a safe/unsafe verdict. The upstream project itself describes these as reference implementations rather than a blanket production-safety guarantee; this report records selected repository evidence for review.

Scan identity

Report schemashadowmcp.repo-evidence.v9
Scannershadowmcp.web-repo-scan.v22 semantics
Scan completed2026-09-23T07:56:00.000Z
Repository branchmain
Scanned commitf46d9578190b476b3501923ea8977d899e8db2cb
Indexation gateIndexable quality gate passed.

Evidence summary

Review priority
Priority review

This is a triage priority, not a repository risk rating.

This repository is directly relevant to MCP implementers and has strong qualified-search potential. The bounded review observed MCP configuration examples in multiple server READMEs, child-process use in filesystem tests, workspace dependency declarations and repository automation.

Evidence categories

MCP configuration

Found

Selected configuration evidence was observed. This does not establish how any user's client is configured.

  • src/fetch/README.mdmcpServers configuration example
  • src/git/README.mdgit server configuration example
  • src/memory/README.mdmemory server configuration example

Shell / command execution

Found

Selected process-spawn evidence was observed in tests. This does not prove a vulnerability or malicious behavior.

  • src/filesystem/__tests__/startup-validation.test.tsspawn imported from child_process
  • src/filesystem/__tests__/structured-content.test.tschild_process spawn used in server test flow

CI/CD automation

Found

Repository automation is present in the bounded root scope.

  • .github/GitHub automation/configuration directory

Supply-chain / dependencies

Found

Root workspace dependencies were observed; this is selected evidence rather than a complete dependency audit.

  • package.jsonnpm workspaces with four @modelcontextprotocol server dependencies and dependency overrides

Scope and limitations

Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1_PLUS_TARGETED_SEARCH. General recursive crawl: NO.

  • Public, selected and bounded repository evidence only.
  • FOUND means evidence observed, not risk or malicious behavior proven.
  • Search matches were reviewed against immutable commit f46d9578190b476b3501923ea8977d899e8db2cb.
  • No repository clone or target-code execution.
  • No raw secret/token values are included.
  • No CVE or package-reputation lookup.
  • No numeric security score and no safe/unsafe verdict.

Repository context

Trust/community metadata is descriptive context only; it is not a security guarantee.

Repository age / activitycreated 2024-11-19 · 673 days old · last push 2026-09-22
Community signalsstars 90,556 · forks 11,683 · open issues 547
OwnershipOrganization · modelcontextprotocol
LicenseOther / repository-declared license
Repository statearchived NO · fork NO · default branch main

Continue the review