Pls Ignore Remote MCP Server is an MCP server that provides developer tools tools to AI agents. Its tool list has not been published yet over stdio, sse and http, requires no API key, and scores 40/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients - only the file and path differ.
{
"mcpServers": {
"math": {
"args": [
"mcp-remote",
"http://localhost:8787/sse"
],
"command": "npx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Let's get a remote MCP server up-and-running on Cloudflare Workers complete with OAuth login!
Run this in your terminal to verify the server starts. Then let us know if it worked - your result helps other developers.
npx -y 'nx' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories - click any category to see the underlying evidence.
Nx: Zip-Slip in the self-hosted remote cache
## Summary The Nx **self-hosted HTTP remote cache** extracts downloaded cache artifacts without constraining where files are written. A malicious — or on-path (MITM) — remote cache server can return a crafted tar archive whose entries escape the cache directory and write to arbitrary locations on the machine running Nx. This arbitrary file write can be escalated to remote code execution. The directly exploitable issue is the self-hosted HTTP remote cache. ## Affected Packages > [!IMPORTANT] >
`nx graph` dev server permissive CORS policy
## Summary The local HTTP server started by `nx graph` sent `Access-Control-Allow-Origin: *` on every response, letting any website a developer visited read the server's responses cross-origin — including the full project graph and the output of the `/help` endpoint, which runs a target's configured help command. The practical impact is typically **cross-origin information disclosure**, but can be arbitrary command injection in rare cases. ## Severity Exploitation requires the developer to b
Malicious code in nx (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: ghsa-malware (8b11cb4be7497510402676b2b593e6a5d3e0dee4e1443996403e8aa496f284f3) ## Summary Malicious versions of the [`nx` package](https://www.npmjs.com/package/nx), as well as some supporting plugin packages, were published to npm, containing code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts. ## Immediate Actions Required ### For all users, check if you were
Be the first to review
Have you used this server?
Share your experience - it helps other developers decide.
Sign in to write a review.
Others in developer-tools
XcodeBuildMCP provides tools for Xcode project management, simulator management, and app utilities.
XcodeBuildMCP provides tools for Xcode project management, simulator management, and app utilities.
Manage Supabase projects — databases, auth, storage, and edge functions
MCP server for using the GitLab API
MCP Security Weekly
Get CVE alerts and security updates for Pls Ignore Remote Mcp Server and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.