Gold-first AI-agent traceback diagnosis, exact fixes, verification, and reusable prescriptions.
MCPpedia last refreshed this data
io.github.JinNing6/cyberhuatuo is an MCP server that gold-first AI-agent traceback diagnosis, exact fixes, verification, and reusable prescriptions. Its tool list has not been published yet over stdio and sse, requires no API key, and scores 54/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients - only the file and path differ.
{
"mcpServers": {
"cyberhuatuo": {
"args": [
"--from",
"cyberhuatuo",
"cyberhuatuo-mcp"
],
"command": "uvx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Gold-first AI-agent traceback diagnosis, exact fixes, verification, and reusable prescriptions.
Run this in your terminal to verify the server starts. Then let us know if it worked - your result helps other developers.
uvx 'langchain-openai' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories - click any category to see the underlying evidence.
PYSEC-2026-76
LangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_messages for image token counting) validated URLs for SSRF protection and then fetched them in a separate network operation with independent DNS resolution. This left a TOCTOU / DNS rebinding window: an attacker-controlled hostname could resolve to a public IP during validation and then to a private/localhost IP during the actual fetch.
Be the first to review
Have you used this server?
Share your experience - it helps other developers decide.
Sign in to write a review.
Others in security / health
MCP server for JavaScript analysis, security auditing, browser automation and hooks
MCP security scanner. CI-native testing, attack simulation, health scoring, and SARIF.
Deterministic security scanning, no model or API key, plus offline-verifiable proof a fix worked.
AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
MCP Security Weekly
Get CVE alerts and security updates for io.github.JinNing6/cyberhuatuo and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.