recao / security
Security review
Is Recao MCP safe to give an agent?
read onlyremoteverifiedhealthy
A factual risk summary built from Recao’s real tool surface, execution model, and verification history — not a vibe. Trust score 70/100.
01What it can do
Only read-style tools observed — no write/destructive tools.
17 tools observed
02Execution model
Runs on the vendor's infrastructure; you connect over the network. No untrusted code runs on your machine, but you grant the hosted service access.
Connects to a remote URL — no local package execution.
03Permissions & auth
No write or destructive tools observed. Absence of a scope isn’t a guarantee — treat unconfirmed access as unknown, not “none.”
04Verification
handshakepassed — tool surface is real
runstools_list:passed · handshake:passed · metadata:passed · tools_list:passed · handshake:passed · metadata:passed · tools_list:passed · handshake:passed · metadata:passed · tools_list:passed
last_checked2026-10-10 16:22Z
sourcesOfficial MCP Registry [p1]
Reduce the risk
Worried about handing an agent raw access? See governed agents in action — Apex gives your AI paced, capped, fully-logged hands with approval queues before anything runs.
Explore Apex →See also: full server page · setup · alternatives