api7/apisix-mcp
APISIX Model Context Protocol (MCP) server is used to bridge large language models (LLMs) with the APISIX Admin API.
37 starsTypeScriptApache-2.0apisixmcpmcp-servertypescript
REVIEWED77/100
Scanned 2026-06-19 · deepseek v1
Dimension breakdown
Security
72/100
8 findings
Quality
72/100
No findings
License
85/100
No findings
Completeness
85/100
No findings
Findings (8)
HIGH: 3MEDIUM: 3LOW: 2
- HIGHsecurityDefault admin key exposed in documentation
- HIGHsecurityArbitrary request forwarding via send_request_to_gateway
- HIGHsecurityUnrestricted resource type in get_resource and delete_resource
- MEDIUMsecurityNo authentication or authorization in MCP server
- MEDIUMsecurityPotential SSRF via upstream host/URL fields
Detailed file:line citations + recommended fixes are visible to the maintainer of this repo after claiming the listing.
Maintainer of this repo?
Claim this listing in 30 seconds with GitHub OAuth. You'll see detailed findings, get notified about matched bounties, and can trigger re-scans on demand.
Claim listingEmbed the badge.
Drop it into your README. Every view backlinks to this verification page.
Markdown
[](https://archimedes.market/r/api7/apisix-mcp)HTML
<a href="https://archimedes.market/r/api7/apisix-mcp"><img src="https://archimedes.market/api/badge/api7/apisix-mcp.svg" alt="Archimedes Trust Verified"/></a>