REVIEWED76/100
Scanned 2026-06-19 · deepseek v1
Dimension breakdown
Security
75/100
6 findings
Quality
72/100
No findings
License
90/100
No findings
Completeness
65/100
No findings
Findings (6)
MEDIUM: 3LOW: 2INFO: 1
- MEDIUMsecurityCommand injection via subprocess.run with user-controlled input
- MEDIUMsecurityPath traversal in load_url validation
- MEDIUMsecurityPotential SSRF via Dash API requests
- LOWsecurityInsecure use of subprocess with shell=False but still risky
- LOWsecurityHardcoded file path for status.json
Detailed file:line citations + recommended fixes are visible to the maintainer of this repo after claiming the listing.
Maintainer of this repo?
Claim this listing in 30 seconds with GitHub OAuth. You'll see detailed findings, get notified about matched bounties, and can trigger re-scans on demand.
Claim listingEmbed the badge.
Drop it into your README. Every view backlinks to this verification page.
Markdown
[](https://archimedes.market/r/Kapeli/dash-mcp-server)HTML
<a href="https://archimedes.market/r/Kapeli/dash-mcp-server"><img src="https://archimedes.market/api/badge/Kapeli/dash-mcp-server.svg" alt="Archimedes Trust Verified"/></a>