← Back to catalog

B

MCP Reference Git

Reference server exposing Git repository tools against a disposable fixture repo.

highautomated scan
Danger score
3.8 / 10
Transparency
high
Last scanned
2026-07-04 08:18:10
Engine
mcpaudit 2.4.0
Source
pypi: mcp-server-git

Automated danger grade: this page reports detected or inferred risk from a scan. It is not an endorsement, certification, or claim that the server is malicious.

Grade history

14 scans on record between 2026-06-20 and 2026-07-04. The grade has not changed across them.

Scanned (UTC)GradeEngineAttributed cause
2026-06-20 06:52Bmcpaudit 2.1.0First scan on record
2026-06-20 07:10Bmcpaudit 2.1.0No change
2026-07-03 02:50Bmcpaudit 2.1.0No change
2026-07-03 09:44Bmcpaudit 2.3.0No change
2026-07-03 10:00Bmcpaudit 2.3.0No change
2026-07-03 10:02Bmcpaudit 2.3.0No change
2026-07-03 10:12Bmcpaudit 2.3.0No change
2026-07-03 10:16Bmcpaudit 2.3.0No change
2026-07-03 12:42Bmcpaudit 2.3.0No change
2026-07-03 13:21Bmcpaudit 2.4.0No change
2026-07-03 14:13Bmcpaudit 2.4.0No change
2026-07-04 08:13Bmcpaudit 2.4.0No change
2026-07-04 08:16Bmcpaudit 2.4.0No change
2026-07-04 08:18Bmcpaudit 2.4.0No change

History as recorded by this registry's own scans. The cause is an attribution from the inputs the registry records — the scanner engine identity and the declared tool surface — not proof of what changed on the server. Generated 2026-08-02.

How to read this grade

Spec-shift exposure

BREAKS against MCP 2026-07-28-rc · confidence high · ruled 2026-07-18

DimensionAreaVerdict
D1Stateless-core compatibilityBREAKS
D2Deprecated-capability relianceREADY
D3Authorization postureN_A
D4Schema and wire conformanceREADY
D5Extensions readinessNOTE

What to change

This is a point-in-time ruling against a release candidate, not the published specification, and it is independent of the danger grade above. Neither figure constrains the other.

Provenance & dispute

Add this badge to your README

Copy the Markdown below only if you want to link readers to the latest danger grade and scan caveats:

[![MCP Trust](https://img.shields.io/endpoint?url=https://mcp-trust.vercel.app/servers/mcp-reference-git/badge.json)](https://mcp-trust.vercel.app/ui/servers/mcp-reference-git)
MCP Trust badge

Findings

SeverityRuleTitleCategoryDetail
lowMCP001File read capabilityfile_readreadOnlyHint=true
lowMCP001File read capabilityfile_readreadOnlyHint=true
lowMCP001File read capabilityfile_readreadOnlyHint=true
lowMCP001File read capabilityfile_readreadOnlyHint=true
mediumMCP001File read capabilityfile_readpath
highMCP002File write capabilityfile_writecommit
mediumMCP001File read capabilityfile_readpath
mediumMCP002File write capabilityfile_writeadd
lowMCP005Destructive operation capabilitydestructivedestructiveHint=true
mediumMCP001File read capabilityfile_readpath
lowMCP001File read capabilityfile_readreadOnlyHint=true
mediumMCP001File read capabilityfile_readpath
mediumMCP002File write capabilityfile_writecreate
mediumMCP001File read capabilityfile_readpath
lowMCP001File read capabilityfile_readreadOnlyHint=true
lowMCP001File read capabilityfile_readreadOnlyHint=true

Score breakdown

DimensionRaw (0–10)WeightWeighted
File access1.8×1.22.16
Network access0.0×1.00.00
Shell execution0.0×2.00.00
Destructive2.0×0.30.60
Exfiltration0.0×0.40.00