EDTBLOCK
MCP for 1C:EDT
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/DitriXNew/EDT-MCP/releases)
[](https://github.com/DitriXNew/EDT-MCP/actions/workflows/build.yml) [](https://github.com/DitriXNew/EDT-MCP/actions/workflows/proxy.yml) [](https://sonarcloud.io/summary/newcode?id=DitriXNewEDT-MCP) [](https://sonarcloud.io/summary/newcode?id=DitriXNewEDT-MCP) [](https://sonarcloud.io/summary/newcode?id=DitriXNewEDT-MCP) [](https://sonarcloud.io/summary/newcode?id=DitriXNewEDT-MCP)
[](https://github.com/DitriXNew/EDT-MCP/actions/workflows/e2e-2026.2.yml)
[](https://github.com/DitriXNew/EDT-MCP/actions/workflows/conformance-2026.2.yml)
Build & Unit Tests, E2E, and MCP Conformance all run on stock GitHub-hosted runners (cloud CI) — no docker image, no self-hosted runner. E2E and Conformance run against EDT 2026.2 (build 2026.2, Eclipse 4.38 / Java 25): the setup step installs a headless EDT of that version on the runner viap2 director. E2E additionally imports the test fixtures into an empty workspace via the plugin's headless bootstrap (EDT_MCP_IMPORT_PROJECTS) and skips the live-infobase tools, so no 1
7a42ce3ce574OBSERVED · 2026-10-06Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
edt-mcp-autopilot-discover | read | Research -> critics -> architect for an EDT-MCP task: produces an implementation spec, a file-disjoint developer partition, and any escalation questions for the human. |
Trust audit
BLOCKgrade F · trust 44/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
- **Inspect payloads with `Invoke-RestMethod`** (PowerShell), not `curl` — curl mangles nested JSON. Tools with a JSON responseType put the data in `result.structuredContent`; `content[0].text` is onl
If a tool returns `tool is disabled` — the current preset (see below) hides it. **Do not try to bypass**; tell the user and suggest switching the preset.
copy-down-1.1.jar
jsoup-1.17.2.jar
snakeyaml-2.2.jar
A separate gate from the e2e business-logic suite: the official `modelcontextprotocol/conformance` suite validates the SERVER against the MCP wire spec (handshake, capabilities, session-id, `isError`,
This suite tests tool **business logic**. The MCP **protocol** itself (initialize handshake, capabilities/version negotiation, `Mcp-Session-Id`, `Accept`/`Content-Type`, `isError`, `ping`, SSE) is a d
`npx @modelcontextprotocol/conformance@latest server --url http://127.0.0.1:8765/mcp --spec-version 2025-11-25 --expected-failures tests/conformance/baseline.yml`
isLoopbackHost(origin, "http://127.0.0.1") || //$NON-NLS-1$
isLoopbackHost(origin, "https://127.0.0.1") || //$NON-NLS-1$
String password = "deadline-secret-value"; //$NON-NLS-1$
String password = "credential-log-probe-secret"; //$NON-NLS-1$
streamable-http
ExtProc.epf
ExtReport.erf
.classpath
.project
.project
.project
.classpath
- name: Download e2e JaCoCo exec (from the triggering E2E run)
hashes[path] = hashlib.sha1(f.read()).hexdigest()
hashlib.sha1(f.read()).hexdigest()
evil = "../../../../etc/passwd"
def _ensure_absent(name, verify=False):
Gates applied: critical_finding, instruction_override, no_behavioural_pass, undeclared_transfer.
7a42ce3ce574full audit observations/trust-audit/mcp-server/ditrixnew__edt.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 7a42ce3ce574 | BLOCK | F | 44 | first audit |
Questions
What is the EDT MCP server?
MCP for 1C:EDT
What tools does EDT expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is EDT safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (44/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does EDT need?
No credential environment variables were found in its source, so it appears to need none.
How does EDT run?
It speaks streamable-http, so it runs as a service you connect to over the network.
How current is this page?
The grade is for one exact copy of the source (7a42ce3ce574), read on 2026-10-06. The repository is watched and re-audited when it changes.