Multi-LLM dev harness, MCP-operable: bugs, cycles, gates. Verdicts are exit codes, never opinions.
MCPpedia last refreshed this data
io.github.jrullan/ducklab is an MCP server that Multi-LLM dev harness, MCP-operable: bugs, cycles, gates. Verdicts are exit codes, never opinions. Its tool list has not been published yet over stdio and sse, requires no API key, and scores 87/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients - only the file and path differ.
{
"mcpServers": {
"io-github-jrullan-ducklab": {
"args": [
"-y",
"vitest"
],
"command": "npx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Multi-LLM dev harness, MCP-operable: bugs, cycles, gates. Verdicts are exit codes, never opinions.
Run this in your terminal to verify the server starts. Then let us know if it worked - your result helps other developers.
npx -y 'vitest' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories - click any category to see the underlying evidence.
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
## Summary `@vitest/mocker` registers a redirect mock's target path without validating it against the dev server's file-serving allowlist. An attacker who can reach the dev server's WebSocket can register a redirect mock pointing outside the project root; when the mocked module is requested, the plugin's `load` hook returns `readFile(<attacker path>)` as the module source, disclosing local files. This is exploitable **without authentication** only through the public `mockerPlugin` / standalone
When Vitest UI server is listening, arbitrary file can be read and executed
### Summary Arbitrary file can be read on Windows when Vitest UI server is listening, especially when exposed to the network. ### Impact Only users that match either of the following conditions are affected: - explicitly exposes the Vitest UI server to the network (using `--api.host` or [`api.host` config option](https://vitest.dev/config/api.html)) - running the Vitest UI or Browser Mode on Windows ### Details The API handler for `/__vitest_attachment__` uses the deprecated `isFileServingAll
Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening
### Summary Arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site WebSocket hijacking (CSWSH) attacks. ### Details When [`api` option](https://vitest.dev/config/#api) is enabled (Vitest UI enables it), Vitest starts a WebSocket server. This WebSocket server did not check Origin header and did not have any authorization mechanism and was vulnerable to CSWSH attacks. https://github.com/vitest-dev/vitest/blob/9a581e1c43e5c02b11e2a8026
Click any tool to inspect its schema.
Be the first to review
Have you used this server?
Share your experience - it helps other developers decide.
Sign in to write a review.
Others in ai-ml
2,500+ scientific tools for AI scientists: life science, research, literature, and more.
The official MCP server implementation for the Perplexity API Platform
An open-source AI agent that brings the power of Gemini directly into your terminal.
Read-only access to 71 Suede skills: discovery, install options, SEO audits, A-F grading.
MCP Security Weekly
Get CVE alerts and security updates for io.github.jrullan/ducklab and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.