← Back to search Server uses network capabilities via: fetch() Server uses filesystem capabilities via: fs, fs sync ops, fs.promises, fs/promises Server uses shell capabilities via: child_process, execSync(), spawn() Server uses env_vars capabilities via: process.env
mcp4openapi
Universal MCP server that generates tools from any OpenAPI specification
C
60.4 / 100
Versions
0.5.6latestMar 2, 2026
0.5.5Mar 2, 2026
0.5.4Feb 27, 2026
0.5.3Feb 25, 2026
0.5.0Feb 22, 2026
+ show 19 moreshow less
0.4.0Feb 15, 2026
0.3.8Feb 10, 2026
0.3.7Feb 8, 2026
0.3.6Feb 8, 2026
0.3.5Feb 8, 2026
0.3.4Feb 5, 2026
0.3.3Feb 4, 2026
0.3.1Feb 3, 2026
0.3.0Jan 31, 2026
0.2.8Dec 20, 2025
0.2.7Dec 17, 2025
0.2.6Dec 16, 2025
0.2.5Dec 15, 2025
0.2.4Dec 5, 2025
0.2.3Dec 1, 2025
0.2.2Nov 30, 2025
0.2.1Nov 30, 2025
0.2.0Nov 27, 2025
0.1.0Nov 8, 2025
Tools 6
get_item annotations: none low
Get item
valid_tool annotations: none low
safe
deep_tool annotations: none low
boundary_tool annotations: none low
safe
t annotations: none low
<b>bad</b>
manage_project_badges annotations: none low
Permissions 4
network medium filesystem low shell high env_vars low Scan Findings 62
low
Tool 'get_item' has no annotations
low
Tool 'valid_tool' has no annotations
low
Tool 'deep_tool' has no annotations
low
Tool 'boundary_tool' has no annotations
low
Tool 't' has no annotations
low
Tool 'manage_project_badges' has no annotations
high
Hardcoded OAuth client secret in davidruzicka-mcp4openapi-eb10bf9/tests/e2e/branches-idempotency.test.ts
high
Hardcoded OAuth client secret in davidruzicka-mcp4openapi-eb10bf9/tests/e2e/auth-oauth.test.ts
high
Hardcoded OAuth client secret in davidruzicka-mcp4openapi-eb10bf9/tests/e2e/transport-http.test.ts
high
Hardcoded OAuth client secret in davidruzicka-mcp4openapi-eb10bf9/src/transport/http-transport.test.ts
high
Hardcoded OAuth client secret in davidruzicka-mcp4openapi-eb10bf9/src/transport/http-transport-security.test.ts
high
Hardcoded OAuth client secret in davidruzicka-mcp4openapi-eb10bf9/src/transport/http-tenant-config.test.ts
high
Hardcoded OAuth client secret in davidruzicka-mcp4openapi-eb10bf9/src/transport/http-transport-payload.test.ts
high
Hardcoded OAuth client secret in davidruzicka-mcp4openapi-eb10bf9/src/transport/http-transport-oauth-toctou.test.ts
high
Hardcoded OAuth client secret in davidruzicka-mcp4openapi-eb10bf9/src/auth/multi-auth.test.ts
medium
Vulnerable dependency: vite@6.0.5 (GHSA-g4jq-h2w9-997c)
high
Hardcoded OAuth client secret in davidruzicka-mcp4openapi-eb10bf9/src/auth/oauth-provider.test.ts
high
Hardcoded OAuth client secret in davidruzicka-mcp4openapi-eb10bf9/src/auth/oauth-pkce-security.test.ts
high
Hardcoded OAuth client secret in davidruzicka-mcp4openapi-eb10bf9/src/testing/oauth-initialization.test.ts
high
Hardcoded OAuth client secret in davidruzicka-mcp4openapi-eb10bf9/src/testing/oauth-security-issues.test.ts
high
Hardcoded OAuth client secret in davidruzicka-mcp4openapi-eb10bf9/src/testing/http-multiauth-integration.test.ts
high
Hardcoded OAuth client secret in davidruzicka-mcp4openapi-eb10bf9/src/testing/vscode-oauth.test.ts
high
Hardcoded OAuth client ID in davidruzicka-mcp4openapi-eb10bf9/src/auth/client-store/policy.test.ts
info
Sandbox failed to start for behavioral verification
medium
Vulnerable dependency: qs@6.14.1 (GHSA-q8mj-m7cp-5q26)
medium
Vulnerable dependency: qs@6.14.1 (GHSA-w7fw-mjwx-w883)
medium
Vulnerable dependency: yaml@2.6.1 (GHSA-48c2-rrv3-qjmp)
medium
Vulnerable dependency: vite@6.0.5 (GHSA-356w-63v5-8wf4)
medium
Vulnerable dependency: vite@6.0.5 (GHSA-4r4m-qw57-chr8)
medium
Vulnerable dependency: vite@6.0.5 (GHSA-4w7w-66w2-5vf9)
medium
Vulnerable dependency: vite@6.0.5 (GHSA-859w-5945-r5v3)
medium
Vulnerable dependency: vite@6.0.5 (GHSA-93m4-6634-74q7)
medium
Vulnerable dependency: vite@6.0.5 (GHSA-fx2h-pf6j-xcff)
medium
Vulnerable dependency: vite@6.0.5 (GHSA-jqfw-vq24-v9c3)
medium
Vulnerable dependency: vite@6.0.5 (GHSA-p9ff-h696-f583)
medium
Vulnerable dependency: vite@6.0.5 (GHSA-v6wh-96g9-6wx3)
medium
Vulnerable dependency: vite@6.0.5 (GHSA-vg6x-rcgg-rjx6)
medium
Vulnerable dependency: vite@6.0.5 (GHSA-x574-m823-4x7w)
medium
Vulnerable dependency: vite@6.0.5 (GHSA-xcj6-pq6g-qj4x)
medium
Vulnerable dependency: vitest@4.0.18 (GHSA-5xrq-8626-4rwp)
medium
Hex string literal (>50 chars) in davidruzicka-mcp4openapi-eb10bf9/scripts/workflow-security.test.ts:197
medium
Buffer.from base64 in davidruzicka-mcp4openapi-eb10bf9/src/tooling/proxy-executor.ts:531
medium
Buffer.from base64 in davidruzicka-mcp4openapi-eb10bf9/src/transport/http-transport.ts:2172
info
package.json metadata
info
Tool: get_item
info
Tool: valid_tool
info
Tool: deep_tool
info
Tool: boundary_tool
info
Tool: t
info
Tool: manage_project_badges
info
Transport: streamable-http
high
Authorization Bearer Token found in davidruzicka-mcp4openapi-eb10bf9/.planning/milestones/v1.0-phases/01-upstream-session-foundation/01-05-PLAN.md
info
Required env vars (142)
medium
Hardcoded OAuth client ID in davidruzicka-mcp4openapi-eb10bf9/src/auth/client-store/policy.test.ts
high
High-risk OAuth scope: admin
info
Sandbox failed to start for output poisoning scan
medium
Permission: network access detected
low
Permission: filesystem access detected
high
Permission: shell access detected
low
Permission: env_vars access detected
info
SBOM generated: 479 components
medium
No build provenance detected (SLSA L0)