Skip to content

Security scan results for opik-mcp -- 93.2/100 (Safe) #98

Description

@AgentSeal

Hi, we scanned opik-mcp through AgentSeal -- 7-stage pipeline: sandbox install, 16 static analyzers, live adversarial probing, AI semantic analysis, cross-tool review, FP filtering, and scoring.

Scored 93.2/100 (SAFE). 10 tools for Opik LLM observability data. One finding worth noting:

Trace retrieval tools (get-trace-by-id, list-traces) return full LLM conversation inputs and outputs. If an agent is connected to a shared Opik workspace, a manipulated agent could harvest conversation history from other users' traces. Adding a readOnlyHint annotation and documenting the data sensitivity in tool descriptions would help hosts make informed decisions about access.

Full report: https://agentseal.org/mcp/https-githubcom-comet-ml-opik-mcp

Badge for your README if you want it:

[![AgentSeal MCP](https://agentseal.org/api/v1/mcp/https-githubcom-comet-ml-opik-mcp/badge)](https://agentseal.org/mcp/https-githubcom-comet-ml-opik-mcp)

AgentSeal MCP

If anything looks off or is a false positive, let us know.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions