Is alibabacloud.mcp-proxy MCP safe to give an agent?
A factual risk summary built from alibabacloud.mcp-proxy’s real tool surface, execution model, and verification history — not a vibe. Trust score 49/100.
No tool handshake yet — capability surface unverified.
Runs locally over stdio — the server process executes on your machine with your user's privileges. Vet the source and package before granting access.
Installs via uvx (`uvx alibabacloud.mcp-proxy`) — it pulls and executes third-party code; pin versions and review the source.
No auth scopes captured yet (scope extraction runs during the sandboxed handshake, gated until configured). Treat unconfirmed scopes as unknown, not as “none.”
Wrap alibabacloud.mcp-proxy in a governed Loadout — scoped permissions, approval rules on write/destructive tools, and audit logging — instead of handing your agent raw access.
Build a governed LoadoutSee also: full server page · setup · alternatives