chihf-mcp-server / security
Security review

Is chihf-mcp-server MCP safe to give an agent?

write capableunknownwrite capablehealthy

A factual risk summary built from chihf-mcp-server’s real tool surface, execution model, and verification history — not a vibe. Trust score 27/100.


01What it can do

Has tools that can create or modify data.

19 tools observedwrite present

02Execution model

Transport not yet confirmed, so the execution model is unknown. Treat as untrusted until verified.

Installs via uvx (`uvx chihf-mcp-server`) — it pulls and executes third-party code; pin versions and review the source.


03Permissions & auth

No write or destructive access inferred from this server’s tools yet. Absence of a scope isn’t a guarantee — treat unconfirmed access as unknown, not “none.”


04Verification
handshakenot confirmed
runshandshake:failed · metadata:passed · handshake:failed · metadata:passed · handshake:failed · metadata:passed · metadata:passed · handshake:failed · metadata:passed · handshake:failed
last_checked2026-07-25 08:47Z
sourcesPyPI [p4]

Reduce the risk

Worried about handing an agent raw access? See governed agents in action — Apex gives your AI paced, capped, fully-logged hands with approval queues before anything runs.

Explore Apex →

See also: full server page · setup · alternatives

Is chihf-mcp-server MCP safe? — risk & permissions — MCPExplorer