Config is the same across clients — only the file and path differ.
{
"mcpServers": {
"mcp-registry-registry": {
"args": [
"-y",
"@mastra/mcp-registry-registry"
],
"command": "npx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Mastra is a framework for building AI-powered applications and agents with a modern TypeScript stack.
Run this in your terminal to verify the server starts. Then let us know if it worked — your result helps other developers.
npx -y '@mastra/mcp-registry-registry' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories — click any category to see the underlying evidence.
Malicious code in @mastra/mcp-registry-registry (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (45ba997a42d41e72f38a36e0a6122b28388f73eb479dc41f7c1b77b6a75f91c8) The package was found to contain malicious code or consuming dependency that contains malicious code ## Source: ghsa-malware (d565975ff7c83efbde8da1110e6be04ef6ae86591cc052f1d9052ae0175b3320) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be
Mastra Docs MCP Server `@mastra/mcp-docs-server` Leads to Information Exposure
The Mastra Docs MCP Server package `@mastra/mcp-docs-server` is a server designed to provide documentation context to AI agentic workflows, such as those used in AI-powered IDEs. **Resources:** * Package URL: [https://www.npmjs.com/package/@mastra/mcp-docs-server](https://www.npmjs.com/package/@mastra/mcp-docs-server) ----- ## Overview The `@mastra/mcp-docs-server` package in versions **0.13.18 and below** is vulnerable to a Directory Traversal attack that results in the disclosure of dir
Make new Mastra projectPrompt to create a new Mastra project by asking questions about project name and LLM provider, then running the setup command and starting the dev server with Mastra Studio
Be the first to review
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Others in other
Pi Coding Agent extension (CLI-first) — routes bash/read/grep/find/ls through lean-ctx CLI for strong token savings. Optional MCP bridge can register advanced tools.
Compress tool outputs, logs, files, and RAG chunks before they reach the LLM. 60-95% fewer tokens, same answers. Library, proxy, MCP server.
97% token reduction for AI coding sessions — zero deps, 21 languages, MCP server
App framework, testing framework, and inspector for MCP Apps.
MCP Security Weekly
Get CVE alerts and security updates for Mcp Registry Registry and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.