Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Security scan results for opik-mcp -- 93.2/100 (Safe) #98

@AgentSeal

Description

@AgentSeal

Hi, we scanned opik-mcp through AgentSeal -- 7-stage pipeline: sandbox install, 16 static analyzers, live adversarial probing, AI semantic analysis, cross-tool review, FP filtering, and scoring.

Scored 93.2/100 (SAFE). 10 tools for Opik LLM observability data. One finding worth noting:

Trace retrieval tools (get-trace-by-id, list-traces) return full LLM conversation inputs and outputs. If an agent is connected to a shared Opik workspace, a manipulated agent could harvest conversation history from other users' traces. Adding a readOnlyHint annotation and documenting the data sensitivity in tool descriptions would help hosts make informed decisions about access.

Full report: https://agentseal.org/mcp/https-githubcom-comet-ml-opik-mcp

Badge for your README if you want it:

[![AgentSeal MCP](https://agentseal.org/api/v1/mcp/https-githubcom-comet-ml-opik-mcp/badge)](https://agentseal.org/mcp/https-githubcom-comet-ml-opik-mcp)

AgentSeal MCP

If anything looks off or is a false positive, let us know.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions