A Model Context Protocol (MCP) server that scrapes, indexes, and searches documentation for third-party software libraries and packages, supporting versioning and hybrid search.
Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
arabold
Source: modelscope · also listed on PulseMCP, mcp.so, npm
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@fastify/static vulnerable to route guard bypass via path traversal
tRPC has possible prototype pollution in `experimental_nextAppDirCaller`
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
APP_VERSIONAWS_ACCESS_KEY_IDAWS_SECRET_ACCESS_KEYAZURE_OPENAI_API_KEYDOCS_EVAL_TOP_KDOCS_MCP_AUTH_ENABLEDDOCS_MCP_CONFIGDOCS_MCP_EMBEDDINGS_VECTOR_DIMENSIONDOCS_MCP_EMBEDDING_MODELDOCS_MCP_HOSTDOCS_MCP_READ_ONLYDOCS_MCP_SCRAPER_ABORT_ON_FAILURE_RATEDOCS_MCP_SCRAPER_DOCUMENT_MAX_SIZEDOCS_MCP_SCRAPER_MAX_PAGESDOCS_MCP_SCRAPER_SECURITY_FILE_ACCESS_ALLOWED_ROOTSDOCS_MCP_SCRAPER_SECURITY_FILE_ACCESS_FOLLOW_SYMLINKSDOCS_MCP_SCRAPER_SECURITY_FILE_ACCESS_INCLUDE_HIDDENDOCS_MCP_SCRAPER_SECURITY_NETWORK_ALLOWED_HOSTSDOCS_MCP_SCRAPER_SECURITY_NETWORK_ALLOW_INVALID_TLSDOCS_MCP_SCRAPER_SKIP_KNOWN_TRACKERSDOCS_MCP_SERVER_PORTS_DEFAULTDOCS_MCP_SERVER_PUBLIC_ORIGINDOCS_MCP_STORE_PATHDOCS_MCP_TELEMETRYENABLE_TEST_LOGSGOOGLE_API_KEYGOOGLE_APPLICATION_CREDENTIALSHOSTNAMELIBRARYLOG_LEVELOPENAI_API_KEY"sk-proj-..." npx @arabold/docs-mcp-server@latestPLAYWRIGHT_CHROMIUM_EXECUTABLE_PATHPLAYWRIGHT_SKIP_BROWSER_DOWNLOADPOSTHOG_API_KEYVITEST_WORKER_IDPORTDependencies
100 dependencies, 1 flagged: playwright
All four hints declared on every tool
10/10 tools missing one or more hints — scrape_docs (missing: readOnlyHint, idempotentHint); refresh_version (missing: readOnlyHint, idempotentHint); search_docs (missing: idempotentHint, openWorldHint), +7 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool inputs are validated
8/10 tool handlers declare input schemas (80%)
Declare an inputSchema with zod/joi/yup on every tool definition.
Tool test coverage
3/10 tools referenced in tests (30%)
Write tests that reference each tool by name so every tool has at least one test.
Shell command execution
1 child_process/subprocess call in production code — runs shell commands (src/cli/utils.ts:94)
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
No arbitrary install scripts
Has postinstall/preinstall script — runs arbitrary code on npm install
Remove postinstall/preinstall hooks unless they’re essential.
Production dependencies are patched
0 critical, 2 high severity in production deps — @fastify/static@10.1.0 (high), @trpc/server@11.4.4 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dependency freshness
5/63 production deps abandoned (no release in 2+ years): gray-matter@2023-07-12 (3.1y), remark-html@2023-11-20 (2.7y), remark-parse@2023-11-20 (2.7y)
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/arabold-docs-mcp-server-1j5ioc)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check