Atlas / MCP servers / getmockd / Mockd

MockdCAUTION

mcp/getmockd/mockd

High-performance, multi-protocol mock server. HTTP, WebSocket, gRPC, MQTT, SSE, GraphQL, SOAP in one binary.

Verdict
CAUTION
Grade
D
Trust score
62 /100
Exposed tools
—
Transport
stdio
License
Apache-2.0
Stars
147
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

One binary. Seven protocols. Zero dependencies.

Mock HTTP, gRPC, GraphQL, WebSocket, MQTT, SSE, and SOAP from a single CLI tool. Import OpenAPI specs. Build digital twins. Let AI agents create mocks for you.

Website · Docs · Samples · Contributing

Quick Start

# Install
curl -sSL https://get.mockd.io | sh

# Start + create a stateful CRUD API in one command
mockd start
mockd add http --path /api/users --stateful users

# It works immediately
curl -X POST localhost:4280/api/users -d '{"name":"Alice","email":"[email protected]"}'
# → {"id":"a1b2c3","name":"Alice","email":"[email protected]"}

curl localhost:4280/api/users
# → {"data":[{"id":"a1b2c3","name":"Alice","email":"[email protected]"}],"meta":{"total":1}}
Read from source at commit 43f42d1c5a69OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (oci)
claude mcp add mockd -- docker run -i --rm ghcr.io/getmockd/mockd:None
03

Trust audit

CAUTIONgrade D · trust 62/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/src/content/docs/protocols/graphql.md:850
token: "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/src/content/docs/protocols/graphql.md:862
token: "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
pkg/oauth/provider_test.go:446
Token:     "expired-refresh-token",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
pkg/oauth/provider_test.go:666
Token:     "refresh-token-for-test",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
pkg/oauth/provider_test.go:868
Token:     "no-scope-refresh-token",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
pkg/tls/certgen_test.go:132
{"wrong type", []byte("-----BEGIN PRIVATE KEY-----\nYQ==\n-----END PRIVATE KEY-----")},
LOWInventory / provenance · inv.hidden_file · CWE-1104
.golangci.yml
.golangci.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.goreleaser.yaml
.goreleaser.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
pkg/admin/admin_test.go:446
{"deep traversal", "../../etc/certs"},
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
pkg/admin/admin_test.go:447
{"hidden in path", "certs/../../../etc"},
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
pkg/mock/mock_test.go:1629
SchemaFile: "../../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
pkg/mock/mock_test.go:1642
SchemaFile: "schemas/../../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
pkg/mock/mock_test.go:1863
ProtoFile: "../../../etc/passwd",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
charts/mockd/templates/NOTES.txt:44
curl -X POST http://127.0.0.1:{{ .Values.mockd.adminPort }}/api/mocks \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
charts/mockd/templates/NOTES.txt:52
curl http://127.0.0.1:{{ .Values.service.port }}/hello
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
pkg/admin/engineclient/client_test.go:88
c := New("http://127.0.0.1:1") // port 1 should refuse
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
pkg/admin/mqtt_handlers_test.go:74
api := NewAPI(0, WithDataDir(t.TempDir()), WithLocalEngineClient(engineclient.New("http://127.0.0.1:1")))
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
pkg/admin/proxy_and_sse_handlers_test.go:57
api := NewAPI(0, WithDataDir(t.TempDir()), WithLocalEngineClient(engineclient.New("http://127.0.0.1:1")))
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
.github/workflows/benchmark.yaml:69
ab -n 100000 -c 200 -k http://localhost:4280/bench 2>&1 | tee /tmp/ab_results.txt
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
benchmarks/run_benchmarks.go:478
sb.WriteString("ab -n 100000 -c 200 -k http://localhost:4280/bench\n\n")
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
benchmarks/run_all.sh:152
"websocket": "${WS_MSG_RATE:-N/A} msg/s, ${WS_LATENCY:-N/A}μs latency",
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
benchmarks/run_all.sh:170
echo "  Latency: ${WS_LATENCY:-N/A}μs"
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
benchmarks/run_benchmarks.go:438
fmt.Fprintf(&sb, "| WebSocket | %.0f ops/s | %.2fμs | %s | Measured |\n",
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
benchmarks/run_benchmarks.go:442
fmt.Fprintf(&sb, "| gRPC | %.0f ops/s | %.2fμs | %s | Measured |\n",
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
benchmarks/run_benchmarks.go:449
fmt.Fprintf(&sb, "| SOAP | %.0f req/s | %.2fμs | %s | Measured |\n",

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 43f42d1c5a69full audit observations/trust-audit/mcp-server/getmockd__mockd.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0743f42d1c5a69CAUTIOND62first audit
05

Questions

What is the Mockd MCP server?

High-performance, multi-protocol mock server. HTTP, WebSocket, gRPC, MQTT, SSE, GraphQL, SOAP in one binary.

Is Mockd safe to connect to an agent?

With care. The audit graded it D (62/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Mockd need?

No credential environment variables were found in its source, so it appears to need none.

How does Mockd run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mockd-docs at 0.0.1.

How current is this page?

The grade is for one exact copy of the source (43f42d1c5a69), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement