Scan result  ·  mcp.roundtable.now
mcp.roundtable.now

Risk

A critical issue, or a lethal-trifecta pattern, was observed on this surface.

scanned 4 months ago
Coverage
Low
Tests run
5
Findings
5 rules · 23 total
Worst severity
Critical

What ran on this surface

3 categories
Prompt InjectionMCP01 · ASI01 · ASI061 finding · 0 clean
CriticalG1Indirect Prompt Injection Gatewayconfidence 75% · 4 findings

Observed: Gateway: tool.

Source
External Content
Gateway: tool "plan-implementation" classified accesses-filesystem (ingestion-kind=file, t...
Sink
Network Send
Canonical sink: tool "get-thread-link" classified sends-network at 70% confidence. Role: n...
Mitigation
Sanitizer Function
No content-sanitiser parameter declared on "plan-implementation". Returned content flows i...
Impact
Data Exfiltration
user-data, exploitability moderate

Fix. This tool ingests content from sources an attacker can influence (web pages, emails, messages, files, database rows, GitHub issues). The content returned is processed directly by the AI without declar...

Model ManipulationMCP01 · MCP06 · MCP072 findings · 0 clean
HighB2Dangerous Parameter Typesconfidence 78% · 2 findings

Observed: code.

Source
User Parameter
code
Sink
Code Evaluation
Parameter "code" (Name advertises generic code evaluation).
Impact
Remote Code Execution
server-host, exploitability moderate

Fix. Parameters that accept file paths, URLs, commands, or SQL should have strict validation: allowlists, path normalization, URL scheme restrictions, or parameterized queries.

MediumB6Schema Allows Unconstrained Additional Propertiesconfidence 75% · 13 findings

Observed: additionalProperties: (unset, defaults to true).

Source
User Parameter
additionalProperties: (unset, defaults to true)
Sink
Config Modification
Handler receives a superset of declared parameters — each extra key is an un-reviewed inpu...
Impact
Config Poisoning
server-host, exploitability moderate

Fix. Set 'additionalProperties: false' on all tool input schemas. Allowing additional properties bypasses all parameter validation, enabling clients to pass arbitrary keys that server-side code may process...

Code VulnerabilitiesMCP03 · MCP05 · MCP072 findings · 0 clean
MediumB1Missing Input Validationconfidence 77% · 3 findings

Observed: 1/3 parameters unconstrained.

Source
User Parameter
1/3 parameters unconstrained.
Sink
Code Evaluation
Tool handler receives raw parameter values with no upfront validation.
Impact
Config Poisoning
server-host, exploitability moderate

Fix. Add input validation constraints to tool parameters. Use maxLength for strings, pattern for format validation, enum for known value sets, and min/max for numeric ranges.

MediumE1No Authentication Requiredconfidence 75%

Observed: Live connection to the MCP server over streamable-http succeeded with no credentials.

Source
Environment
Live connection to the MCP server over streamable-http succeeded with no credentials. `ini...
Sink
Privilege Grant
Full tool authority exposed without identity verification. Any client that reaches the tra...
Mitigation
Auth Check
No authentication mechanism present at the MCP server layer. Reverse-proxy-terminated auth...
Impact
Privilege Escalation
server-host, exploitability trivial

Fix. Require authentication for MCP server connections. Use API keys, bearer tokens, or OAuth to authenticate clients before allowing tool enumeration or invocation.

Not run on this surface
These rules could not be reached by this scan method. They stay listed and counted, so coverage is never overstated. Each says why it did not run and what would unlock it.
7Dependency manifestRules whose declared input (dependency manifest) this scan method did not supply.rescan to unlock
109Source codeRules whose declared input (source code) this scan method did not supply.rescan to unlock
63No execution recordNo record that these rules ran on this surface.rescan

Why these stay. The verdict is coverage aware. A clean result would read "Insufficient coverage", not "Safe", precisely because these rules did not run. Hiding them would let a shallow scan look as thorough as a deep one.

How this server was scanned

The method behind this result was not recorded: the scan predates it. How deep it reached is unknown, and is not implied by anything on this page.

Verifiable Findings

Not yet attested

This server has not been scanned with attestation enabled yet.

How to verify this yourself
# Re-run the analyzer on the signed snapshot and recompute the findings digest
curl -s https://mcp-sentinelapi-production.up.railway.app/api/v1/servers/mcp-roundtable-now-20260516084723-c557b8/attestation.json > att.json
npx mcp-sentinel verify-scan --attestation att.json

# Prove the attestation is in the public transparency log
curl -s https://mcp-sentinelapi-production.up.railway.app/api/v1/servers/mcp-roundtable-now-20260516084723-c557b8/attestation/inclusion.json > incl.json
npx mcp-sentinel transparency verify-inclusion --proof incl.json

Observed behaviorexecuted in sandbox

Declared tool hints vs. what each tool was actually observed to do when executed in our egress-denied sandbox - plus any witnessed tool→tool flow within this one server. This is not cross-server toxic flow, which composes several servers in one config.

Observed behavior not captured for this scan

No observed-behavior record is on file for this server's latest scan.

This is a coverage gap - we did not execute this server’s tools in the sandbox for this scan. It is not a clean result and is not scored as one. To see how observed behavior is rendered when a run does happen, view the illustrative cross-server toxic flow.

Intrinsic here, config-scoped elsewheredual unit

Everything on this page — the verdict, every finding — is mcp.roundtable.now assessed on its own. That is its intrinsic posture. Whether it becomes one leg of a cross-server toxic flow is a different, config-scoped question: it depends on which other servers share its client config, and no verdict on this page changes for it.

Deepen this scan

Every link below opens a form prefilled with this server’s details. Nothing runs until you submit.

mcp.roundtable.now - security audit · MCP Sentinel