Pins an acceptance spec; the verify command and expected output never enter the success contract.
MCPpedia last refreshed this data
Ouroboros is an MCP server that pins an acceptance spec; the verify command and expected output never enter the success contract. Its tool list has not been published yet over stdio, sse and http, requires no API key, and scores 85/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients - only the file and path differ.
{
"mcpServers": {
"ouroboros": {
"args": [
"ouroboros-ai"
],
"command": "uvx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Pins an acceptance spec; the verify command and expected output never enter the success contract.
This server supports HTTP transport. Be the first to test it - help the community know if it works.
Five weighted categories - click any category to see the underlying evidence.
ouroboros-ai Vulnerable to Remote Code Execution via Untrusted Project-Directory .env
### Impact A Remote Code Execution (RCE) vulnerability was discovered in Ouroboros. If a user clones a malicious repository and runs Ouroboros commands within that directory, it can lead to arbitrary code execution and potential system takeover. The vulnerability (CWE-426: Untrusted Search Path & CWE-15: External Control of System Setting) stems from Ouroboros loading the `.env` file from the current working directory. Prior to the patch, execution-affecting environment variables such as `OUROB
ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
### Impact The CVE-2026-47211 fix (0.39.0) added `_UNTRUSTED_ENV_DENYLIST` to stop an untrusted project-directory `.env` from redirecting execution. The denylist was incomplete — several execution-routing keys of the same RCE class were omitted, so a malicious cloned repo can still reach arbitrary command execution by shipping a `.env` (auto-loaded at import, no review step): - **Backend config-home roots** `CODEX_HOME`, `OPENCODE_CONFIG`, `OPENCODE_CONFIG_DIR`, `XDG_CONFIG_HOME`: a spawned ven
Click any tool to inspect its schema.
Be the first to review
Have you used this server?
Share your experience - it helps other developers decide.
Sign in to write a review.
Others in ai-ml
2,500+ scientific tools for AI scientists: life science, research, literature, and more.
MCP server for mobile app automation: verify, control, and debug iOS, Android, TV, and desktop apps
Read-only access to 71 Suede skills: discovery, install options, SEO audits, A-F grading.
Codebase knowledge graph for AI agents — 162 languages, sub-ms queries, 99% fewer tokens.
MCP Security Weekly
Get CVE alerts and security updates for Ouroboros and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.