MCP server · trust report

io.github.mims-harvard/tooluniverse

1 check that ran failed — version behavior — so this release can’t be trusted as-is.

Publisher
io.github.mims-harvard
Repository
github.com/mims-harvard/ToolUniverse
Install
pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse
Versions
30
Inspected
5 of 6 checks · 75%
Scored
2026-08-31 · rubric 1.0.0

What we checked

Six static checks, weighted by risk. Every result reflects only what could be observed in the published package and repository — never intent.

6 checks2 clean3 flagged1 not inspected
  • Injection surface

    unscannable25% of grade

    Tool descriptions/manifest scanned for instruction-injection patterns (imperatives at the model, hidden text, 'ignore previous', data-exfil URLs).

    No tool descriptions, server instructions, prompts, or resources were fetched; nothing to scan for injection.

  • Supply chain

    pass25% of grade

    Package provenance: namespace verification, repo linkage, maintainer count, account age, postinstall scripts, typosquat distance.

    Python build script has no build-time network/exec; repository linkage verified

  • Credential hygiene

    pass15% of grade

    How the server takes secrets (env vs plaintext config vs hardcoded); secrets appearing in tool schemas.

    Reads secrets from the environment (e.g. src/tooluniverse/__init__.py) — the recommended intake shape. PASS = no static red flag; static analysis cannot prove the code honors env-based secret handling at runtime.

  • Permission scope

    warn15% of grade

    Declared tools vs. breadth (filesystem, network, exec); flags shell-exec and unbounded filesystem access.

    has both shell/exec and network egress — capable of download-and-run, though no such path was observed (src/tooluniverse/boltz_tool.py: subprocess.* call; src/tooluniverse/alphafold_tool.py: outbound HTTP/socket call). has both shell/exec and destructive filesystem writes (src/tooluniverse/boltz_tool.py: subprocess.* call; src/tooluniverse/boltz_tool.py: open(…, 'w'/'a'/'x') write-mode file access). discloses shell/exec capability: 6 files (src/tooluniverse/boltz_tool.py, src/tooluniverse/compose_scripts/tool_discover.py, src/tooluniverse/generate_tools.py, +3 more) discloses dynamic code execution: 4 files (src/tooluniverse/compose_tool.py, src/tooluniverse/custom_tool.py, src/tooluniverse/rcsb_pdb_tool.py, +1 more) discloses broad/destructive filesystem access: 7 files (src/tooluniverse/boltz_tool.py, src/tooluniverse/compose_scripts/tool_discover.py, src/tooluniverse/compose_scripts/tool_graph_composer.py, +4 more) Capability DISCLOSURE, not a verdict: static analysis sees the primitive is present and reachable, not whether its use is attacker-controlled.

  • Version behavior

    fail10% of grade

    Diff of tool definitions between versions; new permissions or changed descriptions in a patch release (the postmark-mcp class).

    vs prior 1.4.0 (patch bump): new capability primitive(s) in source: child_process, fs-write, http-client, net, subprocess; new hardcoded outbound host/BCC destination(s): ..., 0.0.0.0, actionability.clinicalgenome.org, aiscientist.tools, alphafold.ebi.ac.uk, alphamissense.hegelab.org, analysis-server, api.archives-ouvertes.fr, api.biorxiv.org, api.cellmodelpassports.sanger.ac.uk, api.cellosaurus.org, api.clinpgx.org, api.core.ac.uk, api.emolecules.com, api.fda.gov, api.gbif.org, api.gdc.cancer.gov, api.genetics.opentargets.org, api.github.com, api.medrxiv.org, api.monarchinitiative.org, api.nvcf.nvidia.com, api.obis.org, api.omim.org, api.oncokb.org, api.openaire.eu, api.openalex.org, api.orphacode.org, api.orphadata.com, api.osf.io, api.pharmgkb.org, api.platform.opentargets.org, api.semanticscholar.org, arxiv.org, azure-ai.hms.edu, batch.rfam.org, bigg.ucsd.edu, biocyc.org, brenda-enzymes.org, build.nvidia.com, cadd.gs.washington.edu, cdnjs.cloudflare.com, chip-atlas.dbcls.jp, chip-atlas.org, civicdb.org, clinicaltables.nlm.nih.gov, clinicaltrials.gov, d3js.org, dailymed.nlm.nih.gov, data.4dnucleome.org, data.cdc.gov, data.rcsb.org, dblp.org, dbpedia.org, deepgo.cbrc.kaust.edu.sa, demo.oncokb.org, depmap.sanger.ac.uk, dgidb.org, doaj.org, docs.gpcrdb.org, doi.org, enamine.net, erepo.clinicalgenome.org, europepmc.org, eutils.ncbi.nlm.nih.gov, evemodel.org, example.com, export.arxiv.org, fair.healthinformationportal.eu, files.rcsb.org, github.com, gnomad.broadinstitute.org, gpcrdb.org, gtexportal.org, hb.flatironinstitute.org, health.api.nvidia.com, hmdb.ca, huggingface.co, integrate.api.nvidia.com, jaspar.elixir.no, maayanlab.cloud, metacyc.org, ml-server, mychem.info, mygene.info, myvariant.info, new.enaminestore.com, odphp.health.gov, omim.org, openrouter.ai, opig.stats.ox.ac.uk, paleobiodb.org, pangolin-37-xwkwwwxdwq-uc.a.run.app, pangolin-38-xwkwwwxdwq-uc.a.run.app, pharos-api.ncats.io, pharos.nih.gov, pubchem.ncbi.nlm.nih.gov, purl.org, pypi.org, pypistats.org, query-api.iedb.org, reactome.org, regulomedb.org, rest.ensembl.org, rest.kegg.jp, rfam.org, rnacentral.org, rxnav.nlm.nih.gov, scholar.archive.org, search.clinicalgenome.org, search.rcsb.org, server, service.azul.data.humancellatlas.org, simbad.cds.unistra.fr, sparql.dsmz.de, spliceai-37-xwkwwwxdwq-uc.a.run.app, spliceai-38-xwkwwwxdwq-uc.a.run.app, stitch.embl.de, string-db.org, w3id.org, webservice.thebiogrid.org, www.atsdr.cdc.gov, www.bindingdb.org, www.biorxiv.org, www.cbioportal.org, www.countyhealthrankings.org, www.dgidb.org, www.disgenet.org, www.ebi.ac.uk, www.emolecules.com, www.encodeproject.org, www.fda.gov, www.guidetopharmacology.org, www.hmdb.ca, www.imgt.org, www.medrxiv.org, www.metabolomicsworkbench.org, www.ncbi.nlm.nih.gov, www.oncokb.org, www.pathwaycommons.org, www.proteinatlas.org, www.semanticscholar.org, www.w3.org, wwwn.cdc.gov, xmlns.com, zitniklab.hms.harvard.edu.

  • Transport config

    warn10% of grade

    Remote servers: TLS and auth mode (none/token/OAuth). Local servers: whether the manifest indicates it phones home.

    manifest/source references telemetry behavior — disclosure

Version history

Each release plotted by grade against the safe line at B. A version that sinks below the line has lost its trusted standing — the shape of a rug-pull.

VersionPublishedGradeScoreInspectedChange
v1.4.1 · current2026-08-12 B77.55/6 · 75%±0
v1.4.02026-07-24 B1003/6 · 55%±0
v1.3.12026-07-02 B87.54/6 · 65%±0
v1.1.112026-03-29 B1003/6 · 55%