Atlas / MCP servers / ditrixnew / EDT

EDTBLOCK

mcp/ditrixnew/edt

MCP for 1C:EDT

Verdict
BLOCK
Grade
F
Trust score
44 /100
Exposed tools
1 1r · 0w · 0d
Transport
streamable-http
License
AGPL-3.0
Stars
293
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/DitriXNew/EDT-MCP/releases)

[](https://github.com/DitriXNew/EDT-MCP/actions/workflows/build.yml) [](https://github.com/DitriXNew/EDT-MCP/actions/workflows/proxy.yml) [](https://sonarcloud.io/summary/newcode?id=DitriXNewEDT-MCP) [](https://sonarcloud.io/summary/newcode?id=DitriXNewEDT-MCP) [](https://sonarcloud.io/summary/newcode?id=DitriXNewEDT-MCP) [](https://sonarcloud.io/summary/newcode?id=DitriXNewEDT-MCP)

[](https://github.com/DitriXNew/EDT-MCP/actions/workflows/e2e-2026.2.yml)

[](https://github.com/DitriXNew/EDT-MCP/actions/workflows/conformance-2026.2.yml)

Build & Unit Tests, E2E, and MCP Conformance all run on stock GitHub-hosted runners (cloud CI) — no docker image, no self-hosted runner. E2E and Conformance run against EDT 2026.2 (build 2026.2, Eclipse 4.38 / Java 25): the setup step installs a headless EDT of that version on the runner via p2 director. E2E additionally imports the test fixtures into an empty workspace via the plugin's headless bootstrap (EDT_MCP_IMPORT_PROJECTS) and skips the live-infobase tools, so no 1
Read from source at commit 7a42ce3ce574OBSERVED · 2026-10-06
02

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
edt-mcp-autopilot-discoverreadResearch -> critics -> architect for an EDT-MCP task: produces an implementation spec, a file-disjoint developer partition, and any escalation questions for the human.
03

Trust audit

BLOCKgrade F · trust 44/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (25)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.claude/skills/edt-mcp-build-test/SKILL.md:37
- **Inspect payloads with `Invoke-RestMethod`** (PowerShell), not `curl` — curl mangles nested JSON. Tools with a JSON responseType put the data in `result.structuredContent`; `content[0].text` is onl
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
rules/en/edt-mcp-tools.md:43
If a tool returns `tool is disabled` — the current preset (see below) hides it. **Do not try to bypass**; tell the user and suggest switching the preset.
Why it matters. asks the agent to act without the user's knowledge
MEDIUMInventory / provenance · inv.binary · CWE-1104
mcp/bundles/com.ditrix.edt.mcp.server/lib/copy-down-1.1.jar
copy-down-1.1.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
mcp/bundles/com.ditrix.edt.mcp.server/lib/jsoup-1.17.2.jar
jsoup-1.17.2.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
mcp/bundles/com.ditrix.edt.mcp.server/lib/snakeyaml-2.2.jar
snakeyaml-2.2.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/skills/edt-mcp-build-test/SKILL.md:56
A separate gate from the e2e business-logic suite: the official `modelcontextprotocol/conformance` suite validates the SERVER against the MCP wire spec (handshake, capabilities, session-id, `isError`,
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/skills/edt-mcp-e2e-testing/SKILL.md:37
This suite tests tool **business logic**. The MCP **protocol** itself (initialize handshake, capabilities/version negotiation, `Mcp-Session-Id`, `Accept`/`Content-Type`, `isError`, `ping`, SSE) is a d
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/skills/edt-mcp-ready-to-deploy/SKILL.md:41
`npx @modelcontextprotocol/conformance@latest server --url http://127.0.0.1:8765/mcp --spec-version 2025-11-25 --expected-failures tests/conformance/baseline.yml`
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp/bundles/com.ditrix.edt.mcp.server/src/com/ditrix/edt/mcp/server/protocol/McpOriginValidator.java:64
isLoopbackHost(origin, "http://127.0.0.1") || //$NON-NLS-1$
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp/bundles/com.ditrix.edt.mcp.server/src/com/ditrix/edt/mcp/server/protocol/McpOriginValidator.java:67
isLoopbackHost(origin, "https://127.0.0.1") || //$NON-NLS-1$
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
mcp/tests/com.ditrix.edt.mcp.server.tests/src/com/ditrix/edt/mcp/server/tools/impl/CreateInfobaseToolTest.java:1559
String password = "deadline-secret-value"; //$NON-NLS-1$
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
mcp/tests/com.ditrix.edt.mcp.server.tests/src/com/ditrix/edt/mcp/server/utils/InfobaseAccessSupportTest.java:524
String password = "credential-log-probe-secret"; //$NON-NLS-1$
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.binary · CWE-1104
tests/ImportFiles/ExtProc.epf
ExtProc.epf
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/ImportFiles/ExtReport.erf
ExtReport.erf
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
mcp/bundles/com.ditrix.edt.mcp.server/.classpath
.classpath
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
mcp/bundles/com.ditrix.edt.mcp.server/.project
.project
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
mcp/features/com.ditrix.edt.mcp.server.feature/.project
.project
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
mcp/targets/default/.project
.project
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
mcp/tests/com.ditrix.edt.mcp.server.tests/.classpath
.classpath
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
.github/workflows/coverage.yml:76
- name: Download e2e JaCoCo exec (from the triggering E2E run)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/e2e/harness.py:2554
hashes[path] = hashlib.sha1(f.read()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/e2e/tools/test_vendor_support_guard.py:56
hashlib.sha1(f.read()).hexdigest()
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/e2e/tools/test_get_check_description.py:181
evil = "../../../../etc/passwd"
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
tests/e2e/tools/test_build_external_objects.py:170
def _ensure_absent(name, verify=False):
Why it matters. certificate verification is disabled
Fix. leave verification on

Gates applied: critical_finding, instruction_override, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-06 · audit v0.4.1 · source sha 7a42ce3ce574full audit observations/trust-audit/mcp-server/ditrixnew__edt.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-067a42ce3ce574BLOCKF44first audit
05

Questions

What is the EDT MCP server?

MCP for 1C:EDT

What tools does EDT expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is EDT safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (44/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does EDT need?

No credential environment variables were found in its source, so it appears to need none.

How does EDT run?

It speaks streamable-http, so it runs as a service you connect to over the network.

How current is this page?

The grade is for one exact copy of the source (7a42ce3ce574), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement