MCP server · trust report

io.github.Khamel83/argus

2 checks that ran failed — supply chain and version behavior — so this release can’t be trusted as-is.

Publisher
io.github.Khamel83
Repository
github.com/Khamel83/argus
Install
pypi:argus-search, pypi:argus-search, pypi:argus-search, pypi:argus-search, pypi:argus-search
Versions
5
Inspected
5 of 6 checks · 75%
Scored
2026-09-03 · rubric 1.0.0

What we checked

Six static checks, weighted by risk. Every result reflects only what could be observed in the published package and repository — never intent.

6 checks0 clean5 flagged1 not inspected
  • Injection surface

    unscannable25% of grade

    Tool descriptions/manifest scanned for instruction-injection patterns (imperatives at the model, hidden text, 'ignore previous', data-exfil URLs).

    No tool descriptions, server instructions, prompts, or resources were fetched; nothing to scan for injection.

  • Supply chain

    fail25% of grade

    Package provenance: namespace verification, repo linkage, maintainer count, account age, postinstall scripts, typosquat distance.

    Python build script executes at build time: network call in build script

  • Credential hygiene

    warn15% of grade

    How the server takes secrets (env vs plaintext config vs hardcoded); secrets appearing in tool schemas.

    tests/test_cli.py: contains a hardcoded OpenAI API key (sk-a…89 (len 34)) — in an example/sample file; verify it is not a real key. tests/test_http_authority.py: assigns a literal to token (call…en (len 12)) — non-provider secret literal; prefer environment intake. tests/test_http_authority.py: assigns a literal to token (actu…en (len 19)) — non-provider secret literal; prefer environment intake. tests/test_maya_outbox.py: assigns a literal to token (secr…en (len 12)) — non-provider secret literal; prefer environment intake. tests/test_mcp_research_report.py: assigns a literal to token (scop…en (len 12)) — non-provider secret literal; prefer environment intake. tests/test_mcp_v2.py: assigns a literal to token (prot…en (len 15)) — non-provider secret literal; prefer environment intake. tests/test_operational_status.py: assigns a literal to token (dedi…en (len 15)) — non-provider secret literal; prefer environment intake. tests/test_provider_evidence.py: assigns a literal to secret (do-n…ss (len 12)) — non-provider secret literal; prefer environment intake. tests/test_provider_transport_conformance.py: assigns a literal to api_key (prov…et (len 15)) — non-provider secret literal; prefer environment intake. tests/test_research_target_contract.py: embeds a PRIVATE KEY block. (in an example/sample file — lower severity, but a real key here still leaks.) tests/test_transport_parity.py: assigns a literal to token (scop…en (len 12)) — non-provider secret literal; prefer environment intake. Reads secrets from the environment (e.g. argus/acquisition/browser_policy.py) — the recommended intake shape.

  • Permission scope

    warn15% of grade

    Declared tools vs. breadth (filesystem, network, exec); flags shell-exec and unbounded filesystem access.

    has both shell/exec and network egress — capable of download-and-run, though no such path was observed (argus/config.py: subprocess.* call; argus/acquisition/transport.py: outbound HTTP/socket call). has both shell/exec and destructive filesystem writes (argus/config.py: subprocess.* call; argus/acceptance_v3/bundle.py: destructive filesystem call (shutil.rmtree/os.remove/etc.)). discloses shell/exec capability: 4 files (argus/config.py, argus/extraction/playwright_extractor.py, argus/recovery/evidence.py, +1 more) discloses broad/destructive filesystem access: 8 files (argus/acceptance_v3/bundle.py, argus/acceptance_v3/contract.py, argus/persistence/search_ledger.py, +5 more) Capability DISCLOSURE, not a verdict: static analysis sees the primitive is present and reachable, not whether its use is attacker-controlled.

  • Version behavior

    fail10% of grade

    Diff of tool definitions between versions; new permissions or changed descriptions in a patch release (the postmark-mcp class).

    vs prior 1.6.2 (patch bump): new capability primitive(s) in source: fs-write, http-client, net, subprocess; new hardcoded outbound host/BCC destination(s): 10.0.0.1, 10.0.0.2, 10.0.0.4, 100.1.2.3, 100.126.13.70, 100.4.5.6, 100.x.x.x, 127.0.0.1, 169.254.169.254, 192.0.2.1, 192.168.1.1, a.bar.co.uk, a.com, a.foo.co.uk, a.foo.github.io, a.news.example.co.uk, a.test, analytics.example.net, api.exa.ai, api.example.test, api.firecrawl.dev, api.github.com, api.linkup.so, api.parallel.ai, api.search.brave.com, api.tavily.com, api.valyu.ai, api.you.com, archive., archive.example, archive.example.com, archive.org, archive.ph, argus-api, argus.internal, argus.invalid, argus.yourdomain.com, attacker.co.uk, attacker.com, attacker.example, authority.example, b, b.bar.co.uk, b.com, b.example.co.uk, b.foo.github.io, b.test, backup.com, backup.example.com, bar.co.uk, blocked.example, blog.example.net, blog.victim.co.uk, brave.com, brightdata.com, browser-policy.invalid, c.bar.github.io, c.com, c.example.co.uk, cached-dns-failure.example, cached.example.com, captions, cdn.example, changed.example, co.uk, com, contributors.test, database.internal, dead.com, dead.example, dead.example.com, destination.test, developer.wolframalpha.com, docs.brightdata.com, docs.example, docs.example.com, docs.example.org, docs.firecrawl.dev, docs.foo.co.uk, docs.github.com, docs.linkup.so, docs.parallel.ai, docs.victim.co.uk, events.example.test, evil.example, evilvictim.co.uk, exa.ai, example.com, example.test, excluded.test, external, external.example.net, fallback.com, filler-, firecrawl.dev, fixture.invalid, fixture.test, foo.home.arpa, foo.invalid, foo.test, free.com, free.example, gateway.example.com, github.com, github.io, google.com, google.serper.dev, homelab, homelab.example.ts.net, html.duckduckgo.com, independent.example.net, inside.test, internal.corp, key.test, khamel.com, limited.example.com, linkup.so, local.test, macmini, mappingproxy.example, maya, maya.example, metadata.internal, modelcontextprotocol.io, must-not-be-called.invalid, notes.example.org, one.com, one.example, one.test, only.test, other.co.uk, other.com, other.example.com, other.example.org, other.test, outside.example.net, outside.example.org, outside.test, paid.com, paid.example.com, parallel.ai, private.example, products.wolframalpha.com, provider.example, provider.test, public.example, pypi.org, r.jina.ai, rank.test, rate-limited-dns.example, redirect.example, redirected.example.test, research.other.com, residential-node, residential.test, same.test, score.test, search.yahoo.com, searxng, seatgeek.com, secret.example, site, site.example.com, source.example, source.test, target.test, tavily.com, test, three.example, two.example, two.test, unaccepted.example.invalid, unrelated.example, unrelated.example.net, user, victim.co.uk, web.archive.org, wolfram.test, worker, worker.internal, www.example.com, www.example.net, www.firecrawl.dev, www.jpl.nasa.gov, www.nytimes.com, www.searchapi.io, www.seatgeek.com, www.wolframalpha.com, www.youtube.com, x.test, xn--bcher-kva.example.com, yahoo.com, ydc-index.io, z.test.

  • Transport config

    warn10% of grade

    Remote servers: TLS and auth mode (none/token/OAuth). Local servers: whether the manifest indicates it phones home.

    manifest/source references tracking behavior — disclosure

Version history

Each release plotted by grade against the safe line at B. A version that sinks below the line has lost its trusted standing — the shape of a rug-pull.

VersionPublishedGradeScoreInspectedChange
v1.6.4 · current2026-09-03 D455/6 · 75%B→D in v1.6.4
v1.6.22026-05-22 B753/6 · 55%