Security audit
MCP Apps
Security checks for vulnerabilities and agentic risk
Overview
The plugin mostly matches its stated MCP Apps purpose, but it exposes a broad gateway for running registered tools and its visibility role appears to be caller-supplied, so access controls need review.
Install only if you need MCP-App UI and gateway support. Limit gateway/operator.write access, treat registered tools and UI resources as trusted code/content, and configure any file-backed resources to narrow, non-sensitive directories.
Static analysis
No suspicious patterns detected.
