Atlas / MCP servers / kuvasz-uptime / Kuvasz

KuvaszBLOCK

mcp/kuvasz-uptime/kuvasz

Kuvasz (pronounce as [ˈkuvɒs]) is an open-source uptime and SSL monitoring service, with multiple notification channels, status pages, IAC support via YAML, Prometheus integration, a complete REST API and many more!

Verdict
BLOCK
Grade
F
Trust score
60 /100
Exposed tools
1 1r · 0w · 0d
Transport
—
License
AGPL-3.0
Stars
636
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/kuvasz-uptime/kuvasz/actions/workflows/main.yml) [](https://github.com/kuvasz-uptime/kuvasz/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) [](https://codecov.io/gh/kuvasz-uptime/kuvasz) [](https://app.fossa.com/projects/git%2Bgithub.com%2Fkuvasz-uptime%2Fkuvasz?ref=badge_shield) [](https://hub.docker.com/r/kuvaszmonitoring/kuvasz) ---

Kuvasz [ˈkuvɒs] is an open-source, self-hosted uptime & SSL monitoring service with **status pages**, designed to help you keep track of your websites and services. It provides a modern, user-friendly interface, a powerful REST API + MCP server, maintenance windows and supports multiple notification channels like email, Discord, Slack, Telegram, Microsoft Teams, Apprise, Pushover, PagerDuty and custom webhooks.

📖 Documentation

Live demo

You can try out Kuvasz on the dedicated demo instance under https://demo.kuvasz-uptime.dev

Use the following credentials to log in:

  • Username: demo
  • Password: secureDemoPassword

🔮 Roadmap

⚡️ Quick start guide

If you want to get started quickly, please refer to the [Deployment guide](https://kuvasz-uptime

Read from source at commit da40e58b2c22OBSERVED · 2026-09-29
02

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
MWreaddesc
03

Trust audit

BLOCKgrade F · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (24)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
app/src/main/kotlin/com/kuvaszuptime/kuvasz/services/docker/ssl/DockerPem.kt:28
private const val PKCS8_HEADER = "-----BEGIN PRIVATE KEY-----"
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
app/src/main/kotlin/com/kuvaszuptime/kuvasz/services/docker/ssl/DockerPem.kt:30
private const val PKCS1_HEADER = "-----BEGIN RSA PRIVATE KEY-----"
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
app/src/main/kotlin/com/kuvaszuptime/kuvasz/services/docker/ssl/DockerPem.kt:32
private const val SEC1_HEADER = "-----BEGIN EC PRIVATE KEY-----"
MEDIUMInventory / provenance · inv.binary · CWE-1104
gradle/wrapper/gradle-wrapper.jar
gradle-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
app/src/test/kotlin/com/kuvaszuptime/kuvasz/services/ui/AppGlobalsFactoryTest.kt:459
apiKeyConfig = ApiKeyConfig().apply { apiKey = "some-non-blank-api-key" },
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
app/src/test/resources/application-push-monitor-conflicting-client-secret.yml:4
client-secret: 'ThisIsASecretThatIsLongEnoughToBeValidButItIsNotUnique'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
app/src/test/resources/application-push-monitor-conflicting-client-secret.yml:7
client-secret: 'ThisIsASecretThatIsLongEnoughToBeValidButItIsNotUnique'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
app/src/test/resources/application-push-monitor-short-client-secret.yml:4
client-secret: 'ThisIsOnlyA35CharacterLongSecret123'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
app/src/uiTest/kotlin/com/kuvaszuptime/kuvasz/uitest/auth/AdminCredentials.kt:5
const val PASSWORD = "e2e-admin-password-123"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
app/src/test/kotlin/com/kuvaszuptime/kuvasz/services/docker/ssl/DockerPemTest.kt:115
.also { Files.writeString(it, "-----BEGIN PRIVATE KEY-----\nMIIE\n") }
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
app/src/test/kotlin/com/kuvaszuptime/kuvasz/services/docker/ssl/DockerPemTest.kt:125
.also { Files.writeString(it, "-----BEGIN PRIVATE KEY-----\nnot really\n-----END PRIVATE KEY-----\n") }
LOWInventory / provenance · inv.hidden_file · CWE-1104
helm/kuvasz-uptime/.helmignore
.helmignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
app/src/test/kotlin/com/kuvaszuptime/kuvasz/services/UptimeCheckerE2ETest.kt:59
val otherHostMockServerUrl = "http://127.0.0.1:1080"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
app/src/test/kotlin/com/kuvaszuptime/kuvasz/services/docker/DockerDaemonUrlTest.kt:170
val address = DockerDaemonUrl.parse("http://10.0.0.5", tls = null)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
app/src/test/kotlin/com/kuvaszuptime/kuvasz/services/docker/DockerDaemonUrlTest.kt:181
DockerDaemonUrl.parse("http://10.0.0.5", tls = tlsMaterial())
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
app/src/test/kotlin/com/kuvaszuptime/kuvasz/services/docker/DockerDaemonUrlTest.kt:190
val address = DockerDaemonUrl.parse("https://10.0.0.5", tls = null)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
app/src/test/kotlin/com/kuvaszuptime/kuvasz/services/docker/DockerDaemonUrlTest.kt:201
val address = DockerDaemonUrl.parse("https://10.0.0.5:8443", tls = null)
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/docs/management/docker-hosts.md:239
- **Mutual TLS authenticates, but it doesn't authorize.** A valid client certificate gives **full access** to the daemon, so treat the client key as a root credential, and don't reuse it for anything 
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/docs/setup/configuration.md:327
By default **any user your OIDC provider successfully authenticates is allowed to sign in** and is granted full access. If your provider serves a broader audience than the people who should access _Ku
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/docs/setup/configuration.md:330
Without an email allowlist, **every user the OIDC provider can authenticate gets full access to _Kuvasz_** — including the REST API. If your provider is shared with other applications, backed by a pub
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/docs/management/docker-hosts.md:5
Docker hosts are **defined in your configuration file**, similarly to the [integrations](integrations.md), and every monitor refers to its host **by name**. They can't be created or modified on the UI
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/docs/setup/configuration.md:45
If it's set to `false`, the authentication will be completely disabled, and you can access the web UI or the API without any credentials.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/docs/management/integrations.md:599
4. To get your chat ID, send a message to your desired chat and then visit `https://api.telegram.org/bot<YourApiToken>/getUpdates` in your browser, where `<YourApiToken>` is the token you received fro
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/docs/setup/configuration.md:188
Once OIDC is enabled, the **Settings** page (and the `/settings` endpoint of the [REST API](../features/api.md)) shows the effective OIDC configuration — the issuer, client ID, the exact redirect (cal
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha da40e58b2c22full audit observations/trust-audit/mcp-server/kuvasz-uptime__kuvasz.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-29da40e58b2c22BLOCKF60first audit
05

Questions

What is the Kuvasz MCP server?

Kuvasz (pronounce as [ˈkuvɒs]) is an open-source uptime and SSL monitoring service, with multiple notification channels, status pages, IAC support via YAML, Prometheus integration, a complete REST API and many more!

What tools does Kuvasz expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Kuvasz safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (60/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Kuvasz need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (da40e58b2c22), read on 2026-09-29. The repository is watched and re-audited when it changes.

Advertisement