Back to plugin

Security audit

automatelab-content-distribution-mcp

Security checks for vulnerabilities and agentic risk

Overview

This is a real content-publishing MCP, but account scoping, credential handling, and install metadata need review before use.

Install only if you intend to let an agent publish to your external accounts. Verify the package source before running because one config points to a different npm scope, use least-privilege tokens, protect ~/.distribution-mcp/profiles.yaml, avoid shared machines, and require your own review step before any publish, schedule, drain, or unpublish action.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/adapters/bluesky.ts:26
Evidence
body: JSON.stringify({ identifier: BLUESKY_IDENTIFIER, password: [REDACTED] }),

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/adapters/devto.ts:19
Evidence
const apiKey = [REDACTED]["DEV_TO_API_KEY"];