Atlas / MCP servers / laigeoffer / PmHub

PmHubBLOCK

mcp/laigeoffer/pmhub

PmHub,一个基于 SpringCloud & LLM 的智能项目管理系统,该项目旨在帮助小伙伴们快速掌握微服务/分布式项目的架构设计和开发流程。如果你想在校招或者社招中拿到一个满意的 offer,PmHub 将是一个非常 nice 的选择😄。

Verdict
BLOCK
Grade
F
Trust score
42 /100
Exposed tools
200 405r · 16w · 7d
Transport
—
License
MIT
Stars
578
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

PmHub,一个基于 SpringCloud & LLM 的智能项目管理系统

PmHub 是一套基于 SpringCloud & LLM 的微服务智能项目管理系统,这个项目旨在帮助小伙伴们快速掌握微服务/分布式项目的架构设计和开发流程,如果想在校招或者社招中拿到一个满意的 offer,PmHub 将是一个非常 nice 的选择。

项目亮点

  • 热门技术:采用时下企业最热门的技术框架,如 SpringCloud-Gateway、Nacos、Sentinel 等,主打一个硬核,与真实的企业项目接轨。
  • 单体与微服务:提供单体和微服务两个版本,完美照顾零基础和需要进阶的同学,带大家体验从单体到微服务架构的改造全过程,并深入理解两种架构的优缺点。
  • 硬核面试题:我们将结合付费球友的实际面试体验,为大家提供可以真正吊打面试官的真是面试场景和题目,并提供 1v1 的简历修改服务,主打一个投了就有、面了就拿 offer 的快乐体感。
  • 代码质量:由蚂蚁金服工作过的技术专家苍何亲自下场,严格遵循代码规范和最佳实践,帮大家养成优雅的代码编写习惯。
  • 持续集成:提供持续集成和持续部署的完整配置,带你从 0-1 用 Docker 上线 生产环境级别的真实项目。
  • 产品设计:提供完整的产品设计文档,包括产品需求、产品架构、产品原型等,这是别的项目不曾给你的,但工作后又不可或缺的能力。
  • 企业工作流:提供企业级的工作流系统,代码完全开源,你可以在此基础上进行二开,为公司节省巨额的研发成本,从而升职加薪。

一、项目简介

PmHub 包括认证、流程、项目管理、用户、网关等服务。包含了 Redis 缓存、RocketMQ 消息队列、Docker 容器化、Jenkins 自动化部署、Spring Security 安全框架、Nacos 服务注册和发现、Sentinel 熔断限流、Seata 分布式事务、Spring Boot Actuator 服务监控、SkyWalking 链路追踪、OpenFeign 服务调用,Vue3 前端框架等互联网开发中需要用到的主流技术栈,可以帮助同学们快速掌握微服务/分布式项目的核心知识点。

并且同时 PmHub 也是一套企业工作流的开发框架,您可以根据自身需求,快速定制出适合自己公司的企业工作流系统。

Read from source at commit f9ecf83f9402OBSERVED · 2026-09-29
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add form-gen-tinymce -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "form-gen-tinymce": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (200)

405 read · 16 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
-moz-boxreadThe element lays out its contents using flow layout (block-and-inline layout). Standardized as
-moz-grabreadIndicates that something can be grabbed.
-moz-grabbingreadIndicates that something is being grabbed.
-moz-hidden-unscrollablereadSame as the standardized
-moz-inline-boxreadInline-level flex container. Standardized as
-moz-zoom-inreadIndicates that something can be zoomed (magnified) in.
-moz-zoom-outreadIndicates that something can be zoomed (magnified) out.
-ms-autohiding-scrollbarreadIndicates the element displays auto-hiding scrollbars during mouse interactions and panning indicators during touch and keyboard interactions.
-ms-flexboxreadThe element lays out its contents using flow layout (block-and-inline layout). Standardized as
-ms-gridreadThe element generates a principal grid container box, and establishes a grid formatting context.
-ms-inline-flexboxreadInline-level flex container. Standardized as
-ms-inline-gridreadInline-level grid container.
-ms-pagereadThe box
-webkit-boxreadThe element lays out its contents using flow layout (block-and-inline layout). Standardized as
-webkit-flexreadThe element lays out its contents using flow layout (block-and-inline layout).
-webkit-grabreadIndicates that something can be grabbed.
-webkit-grabbingreadIndicates that something is being grabbed.
-webkit-inline-boxreadInline-level flex container. Standardized as
-webkit-inline-flexreadInline-level flex container.
-webkit-stickyreadThe box
-webkit-zoom-inreadIndicates that something can be zoomed (magnified) in.
-webkit-zoom-outreadIndicates that something can be zoomed (magnified) out.
100readThin
200readExtra Light (Ultra Light)
300readLight
400readNormal
500readMedium
600readSemi Bold (Demi Bold)
700readBold
800readExtra Bold (Ultra Bold)
900readBlack (Heavy)
abbrreadThis attribute contains a short abbreviated description of the cell
abovereadThe reflection appears above the border box.
absolutereadThe box
acceptreadA comma-separated list of content types that the server accepts.\n\n**Usage note:** This attribute has been removed in HTML5 and should no longer be used. Instead, use the [
accumulatereadIf the ancestor container element has a property of new, then all graphics elements within the current container are rendered both on the parent
activereadThe input method editor is initially active; text entry is performed using it unless the user specifically dismisses it.
additional-ligaturesreadEnables display of additional ligatures.
additivereadRepresents “sign-value” numbering systems, which, rather than using reusing digits in different positions to change their value, define additional digits with much larger values, so that the value of the number can be obtained by adding all the digits together.
afterreadThe ruby text appears after the base. This is a relatively rare setting used in ideographic East Asian writing systems, most easily found in educational text.
aliasreadIndicates an alias of/shortcut to something is to be created. Often rendered as an arrow with a small curved arrow next to it.
alignreadSets the alignment of the rule on the page. If no value is specified, the default value is
alinkreadColor of text for hyperlinks when selected. _This method is non-conforming, use CSS [
allreadThe element spans across all columns. Content in the normal flow that appears before the element is automatically balanced across all columns before the element appear.
all-petite-capsreadEnables display of petite capitals for both upper and lowercase letters.
all-scrollreadIndicates that the something can be scrolled in any direction. Often rendered as arrows pointing up, down, left, and right with a dot in the middle.
all-small-capsreadEnables display of small capitals for both upper and lowercase letters.
allowreadSpecifies a [feature policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/Feature_Policy) for the
allowpaymentrequestwriteSet to
alphareadAlpha values of the mask layer image should be used as the mask values.
alphabeticreadThe underline is aligned with the alphabetic baseline. In this case the underline is likely to cross some descenders.
alternatereadThe animation cycle iterations that are odd counts are played in the normal direction, and the animation cycle iterations that are even counts are played in a reverse direction.
alternate-reversereadThe animation cycle iterations that are odd counts are played in the reverse direction, and the animation cycle iterations that are even counts are played in a normal direction.
alwaysdestructiveAlways force a page break before/after the generated box.
archivereadA space-separated list of URIs for archives of resources for the object.
armenianreadTraditional uppercase Armenian numbering.
asreadThis attribute is only used when
autoreadComputes to the value of
autocapitalizereadThis is a nonstandard attribute used by iOS Safari Mobile which controls whether and how the text value for textual form control descendants should be automatically capitalized as it is entered/edited by the user. If the
autocompletereadThe use of this attribute on a [
avoidreadAvoid a break before/after the principal box.
avoid-columnreadAvoid a column break before/after the principal box.
avoid-pagereadAvoid a page break before/after the principal box.
axisreadThis attribute contains a list of space-separated strings. Each string is the
backgroundreadURI of a image to use as a background. _This method is non-conforming, use CSS [
backwardsreadThe beginning property value (as defined in the first @keyframes at-rule) is applied before the animation is displayed, during the period defined by
balancereadBalance content equally between columns, if possible.
baselinereadIf the flex item’s inline axis is the same as the cross axis, this value is identical to
beforereadThe ruby text appears before the base. This is the most common setting used in ideographic East Asian writing systems.
belowreadThe underline is aligned with the under edge of the element’s content box.
bevelreadIndicates that a bevelled corner is to be used to join path segments.
bgcolorreadBackground color for the document. _This method is non-conforming, use CSS [
bidi-overridereadInside the element, reordering is strictly in sequence according to the
blockreadThe element generates a block-level box
block-axisreadElements are oriented along the box
boldreadSame as 700
bolderreadSpecifies the weight of the face bolder than the inherited value.
borderreadThe width of a border around the control, in pixels.
border-boxreadThe specified width and height (and respective min/max properties) on this element determine the border box of the element.
bothreadBoth forwards and backwards fill modes are applied.
bottomreadEquivalent to
bottommarginreadThe margin of the bottom of the body. _This method is non-conforming, use CSS [
breakreadIf the content fits within the CSS Region, then this property has no effect.
break-allreadLines may break between any two grapheme clusters for non-CJK scripts.
break-wordreadAn unbreakable
btreadBottom-to-top block flow. Layout is horizontal.
buttreadIndicates that the stroke for each subpath does not extend beyond its two endpoints.
capitalizereadPuts the first typographic letter unit of each word in titlecase.
captiondestructiveThe font used for captioned controls (e.g., buttons, drop-downs, etc.).
cellwriteIndicates that a cell or set of cells may be selected. Often rendered as a thick plus-sign with a dot in the middle.
centerreadLines are packed toward the center of the flex container.
chainedreadThe nearest zoomable parent element begins zooming when the user hits a zoom limit during a manipulation. No bounce effect is shown.
charreadAny of the range of character values available to the -ms-layout-grid-char property.
circlereadA hollow circle.
citereadThis attribute defines the URI of a resource that explains the change, such as a link to meeting minutes or a ticket in a troubleshooting system.
classidreadThe URI of the object
cleardestructiveInline flow content can only wrap on top and bottom of the exclusion and must leave the areas to the start and end edges of the exclusion box empty.
clipreadClip inline content that overflows. Characters may be only partially rendered.
clonereadEach box is independently wrapped with the border and padding.
codebasereadThe base path used to resolve relative URIs specified by **classid**, **data**, or **archive**. If not specified, the default is the base URI of the current document.
codetypereadThe content type of the data specified by **classid**.
col-resizereadIndicates that the item/column can be resized horizontally. Often rendered as arrows pointing left and right with a vertical bar separating them.
collapsereadSelects the collapsing borders model.
colorreadSets the color of the rule through color name or hexadecimal value.
color-burnreadDarkens the backdrop color to reflect the source color.
color-dodgereadBrightens the backdrop color to reflect the source color.
colsreadContains the _preferred_ count of characters that a line should have. It was a non-standard synonym of [
columndestructiveAlways force a column break before/after the principal box.
column-reversereadSame as
common-ligaturesreadEnables display of common ligatures.
compactreadThis Boolean attribute hints that the list should be rendered in a compact style. The interpretation of this attribute depends on the user agent and it doesn\
containreadScale the image, while preserving its intrinsic aspect ratio (if any), to the largest size such that both its width and its height can fit inside the background positioning area.
contentreadAll containment rules except size are applied to the element.
content-boxreadBehavior of width and height as specified by CSS2.1. The specified width and height (and respective min/max properties) apply to the width and height respectively of the content box of the element.
contentsreadThe element itself does not generate any boxes, but its children and pseudo-elements still generate boxes as normal.
context-menureadA context menu is available for the object under the cursor. Often rendered as an arrow with a small menu-like graphic next to it.
copyreadIndicates something is to be copied. Often rendered as an arrow with a small plus sign next to it.
coverreadScale the image, while preserving its intrinsic aspect ratio (if any), to the smallest size such that both its width and its height can completely cover the background positioning area.
crisp-edgesreadThe image must be scaled with an algorithm that preserves contrast and edges in the image, and which does not smooth colors or introduce blur to the image in the process.
crispEdgesreadEmphasize the contrast between clean edges of artwork over rendering speed and geometric precision.
crosshairreadA simple crosshair (e.g., short line segments resembling a
cspreadA [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) enforced for the embedded resource. See [
currentreadIndicates that the user agent should target the frame that the element is in.
cyclicreadCycles repeatedly through its provided symbols, looping back to the beginning when it reaches the end of the list.
darkenreadSelects the darker of the backdrop and source colors.
dashedreadProduces a dashed line style.
decimalreadWestern decimal numbers.
decimal-leading-zeroreadDecimal numbers padded by initial zeros.
declarereadThe presence of this Boolean attribute makes this element a declaration only. The object must be instantiated by a subsequent
decodingreadProvides an image decoding hint to the browser. The allowed values are:
defaultreadThe platform-dependent default cursor. Often rendered as an arrow.
densereadIf specified, the auto-placement algorithm uses a “dense” packing algorithm, which attempts to fill in holes earlier in the grid if smaller items come up later.
diagonal-fractionsreadEnables display of lining diagonal fractions.
differencereadSubtracts the darker of the two constituent colors from the lighter color..
digitsreadAttempt to typeset horizontally each maximal sequence of consecutive ASCII digits (U+0030–U+0039) that has as many or fewer characters than the specified integer such that it takes up the space of a single character within the vertical line box.
dirreadThe direction in which text should be rendered in this element
disabledreadThe input method editor is disabled and may not be activated by the user.
discreadA filled circle.
discretionary-ligaturesreadEnables display of discretionary ligatures.
distributereadLines are evenly distributed in the flex container, with half-size spaces on either end.
dottedreadProduces a dotted line.
doublereadProduces a double line.
double-tap-zoomreadThe element will zoom on double-tap.
e-resizereadIndicates that east edge is to be moved.
ellipsisreadRender an ellipsis character (U+2026) to represent clipped inline content.
embedreadIf the element is inline-level, this value opens an additional level of embedding with respect to the bidirectional algorithm. The direction of this embedding level is given by the
endreadThe items are packed flush to each other toward the end edge of the alignment container in the main axis.
evenoddreadDetermines the ‘insideness’ of a point on the canvas by drawing a ray from that point to infinity in any direction and counting the number of path segments from the given shape that the ray crosses.
ew-resizereadIndicates a bidirectional east-west resize cursor.
exclusionreadProduces an effect similar to that of the Difference mode but lower in contrast.
extendsreadUse the algorithm of another counter style, but alter other aspects.
falsereadThe element does not contain an accelerator key sequence.
fillreadCauses the middle part of the border-image to be preserved.
fit-contentreadUse the fit-content inline size or fit-content block size, as appropriate to the writing mode.
fixedreadThe background is fixed with regard to the viewport. In paged media where there is no viewport, a
flatreadAll children of this element are rendered flattened into the 2D plane of the element.
flexreadThe element generates a principal flex container box and establishes a flex formatting context.
flex-endreadLines are packed toward the end of the flex container.
flex-startwriteLines are packed toward the start of the flex container.
flexboxreadThe element lays out its contents using flow layout (block-and-inline layout). Standardized as
flipreadAfter rotating by the precededing angle, the image is flipped horizontally. Defaults to 0deg if the angle is ommitted.
flow-rootreadThe element generates a block container box, and lays out its contents using flow layout.
formreadThis attribute associates the element with a
forwardsreadThe final property value (as defined in the last @keyframes at-rule) is maintained after the animation completes.
from-imagereadIf the image has an orientation specified in its metadata, such as EXIF, this value computes to the angle that the metadata specifies is necessary to correctly orient the image.
full-widthreadEnables rendering of full-width variants.
geometricPrecisionreadEmphasize geometric precision over speed and crisp edges.
georgianreadTraditional Georgian numbering.
grabreadIndicates that something can be grabbed.
grabbingreadIndicates that something is being grabbed.
gridreadThe element generates a principal grid container box, and establishes a grid formatting context.
grippersreadGrippers are always on.
hard-lightreadMultiplies or screens the colors, depending on the source color value.
helpreadHelp is available for the object under the cursor. Often rendered as a question mark or a balloon.
hiddenreadBack side is hidden.
hidereadNo borders or backgrounds are drawn around/behind empty cells.
historical-formsreadEnables display of historical forms.
historical-ligaturesreadEnables display of historical ligatures.
horizontalreadThe box displays its children from left to right in a horizontal line.
horizontal-tbreadTop-to-bottom block flow direction. The writing mode is horizontal.
iconreadThe (pseudo-)element is replaced in its entirety by the resource referenced by its
ideograph-alphareadCreates 1/4em extra spacing between runs of ideographic letters and non-ideographic letters, such as Latin-based, Cyrillic, Greek, Arabic or Hebrew.
ideograph-numericreadCreates 1/4em extra spacing between runs of ideographic letters and numeric glyphs.
ideograph-parenthesisreadCreates extra spacing between normal (non wide) parenthesis and ideographs.
ideograph-spacereadExtends the width of the space character while surrounded by ideographs.
importancereadIndicates the relative importance of the resource. Priority hints are delegated using the values:
inactivereadThe input method editor is initially inactive, but the user may activate it if they wish.
infinitereadCauses the animation to repeat forever.
inlinereadThe element generates an inline-level box.
inline-axisreadElements are oriented vertically.
inline-blockreadA block box, which itself is flowed as a single inline box, similar to a replaced element. The inside of an inline-block is formatted as a block box, and the box itself is formatted as an inline box.
inline-endreadA keyword indicating that the element must float on the end side of its containing block. That is the right side with ltr scripts, and the left side with rtl scripts.
inline-flexreadInline-level flex container.
inline-flexboxreadInline-level flex container. Standardized as
inline-startwriteA keyword indicating that the element must float on the start side of its containing block. That is the left side with ltr scripts, and the right side with rtl scripts.
inline-tablereadInline-level table wrapper box containing table box.
insetdestructiveChanges the drop shadow from an outer shadow (one that shadows the box onto the canvas, as if it were lifted above the canvas) to an inner shadow (one that shadows the canvas onto the box, as if the box were cut out of the canvas and shifted behind it).
insidereadThe marker box is outside the principal block box, as described in the section on the ::marker pseudo-element below.
integrityreadThis attribute contains inline metadata that a user agent can use to verify that a fetched resource has been delivered free of unexpected manipulation. See [Subresource Integrity](https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity).
inter-clusterreadJustification primarily changes spacing at word separators and at grapheme cluster boundaries in clustered scripts. This value is typically used for Southeast Asian scripts such as Thai.
04

Trust audit

BLOCKgrade F · trust 42/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (7 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALObfuscation / stealth · obf.decode_then_exec · CWE-506, CWE-94
pmhub-ui/dist/static/js/chunk-a45731e8.e1747f74.js:1
atob( ... new Function(
Why it matters. decodes a payload and executes it
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
pmhub-boot/pmhub-ui/src/utils/generator/js.js:144
rules.push(`{ pattern: ${eval(item.pattern)}, message: '${item.message}', trigger: '${trigger[conf.tag]}' }`)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
pmhub-boot/pmhub-ui/src/utils/generator/parser.js:210
item.pattern && (item.pattern = eval(item.pattern))
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
pmhub-ui/dist/static/js/chunk-53dbcb75.1b760542.js:1
(window["webpackJsonp"]=window["webpackJsonp"]||[]).push([["chunk-53dbcb75"],{"00fd":function(e,t,n){var i=n("9e69"),r=Object.prototype,s=r.hasOwnProperty,o=r.toString,a=i?i.toStringTag:void 0;functio
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
pmhub-ui/src/utils/generator/js.js:144
rules.push(`{ pattern: ${eval(item.pattern)}, message: '${item.message}', trigger: '${trigger[conf.tag]}' }`)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
pmhub-ui/src/utils/generator/parser.js:210
item.pattern && (item.pattern = eval(item.pattern))
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
pmhub-boot/pmhub-ui/.node-version
.node-version
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
pmhub-ui/.node-version
.node-version
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
pmhub-ui/dist/html/ie.html.gz
ie.html.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
pmhub-ui/dist/index.html.gz
index.html.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
pmhub-ui/dist/libs/monaco-editor/vs/base/worker/workerMain.js.gz
workerMain.js.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
pmhub-boot/pmhub-ui/vue.config.js:38
target: `http://127.0.0.1:5010`,
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
pmhub-ui/vue.config.js:38
target: `http://127.0.0.1:6880`,
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
pmhub-boot/pmhub-admin/src/main/resources/application-local.yml:115
privateKey: 12MIGTAgEAMBMGByqGSM49AgEGCCqBHM9VAYItBHkwdwIBAQQgElDjS1Gg6QjpSbfDe0Envb05XEDU9n1fx7wd8ezlnI6gCgYIKoEcz1UBgi2hRANCAAQw/nkFKApgqpwNXLhbjQP6T9vAM4NI86jiKPREJnGwStnLqg3Yx6e3ToBxRA+I4/In8DyIft
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
pmhub-boot/pmhub-admin/src/main/resources/application-pre.yml:111
privateKey: MIGTAgEAMBMGByqGSM49AgEGCCqBHM9VAYItBHkwdwIBAQQgElDjS1Gg6QjpSbfDe0Envb05XEDU9n1fx7wd8ezlnI6gCgYIKoEcz1UBgi2hRANCAAQw/nkFKApgqpwNXLhbjQP6T9vAM4NI86jiKPREJnGwStnLqg3Yx6e3ToBxRA+I4/In8DyIftO9
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
pmhub-boot/pmhub-ui/src/plugins/package/theme/index.scss:20
background: url('data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iNDAiIGhlaWdodD0iNDAiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyI+PGRlZnM+PHBhdHRlcm4gaWQ9ImEiIHdpZHRoPSI0MCIgaGVpZ2h0PSI0MCIgcGF0dGVyblVua
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
pmhub-base/pmhub-base-core/src/main/java/com/laigeoffer/pmhub/base/core/constant/TokenConstants.java:23
public final static String SECRET = "abcdefghijklmnopqrstuvwxyzabcdefghijklmnopqrstuvwxyzabcdefghijklmnopqrstuvwxyzabcdefghijklmnopqrstuvwxyz";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
pmhub-boot/pmhub-ui/public/libs/monaco-editor/vs/basic-languages/bat/bat.js:7
define("vs/basic-languages/bat/bat",["require","exports"],(function(e,s){"use strict";Object.defineProperty(s,"__esModule",{value:!0}),s.language=s.conf=void 0,s.conf={comments:{lineComment:"REM"},bra
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
pmhub-boot/pmhub-ui/public/libs/monaco-editor/vs/basic-languages/cameligo/cameligo.js:7
define("vs/basic-languages/cameligo/cameligo",["require","exports"],(function(e,o){"use strict";Object.defineProperty(o,"__esModule",{value:!0}),o.language=o.conf=void 0,o.conf={comments:{lineComment:
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
pmhub-boot/pmhub-ui/public/libs/monaco-editor/vs/basic-languages/clojure/clojure.js:7
define("vs/basic-languages/clojure/clojure",["require","exports"],(function(e,t){"use strict";Object.defineProperty(t,"__esModule",{value:!0}),t.language=t.conf=void 0,t.conf={comments:{lineComment:";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
pmhub-boot/pmhub-ui/public/libs/monaco-editor/vs/basic-languages/coffee/coffee.js:7
define("vs/basic-languages/coffee/coffee",["require","exports"],(function(e,n){"use strict";Object.defineProperty(n,"__esModule",{value:!0}),n.language=n.conf=void 0,n.conf={wordPattern:/(-?\d*\.\d\w*
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
always, caption, clear, column, inset, no-drop, page
Why it matters. 7 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
pmhub-boot/pmhub-ui/.env.development
.env.development
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
pmhub-boot/pmhub-ui/.env.production
.env.production
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
pmhub-boot/pmhub-ui/.env.staging
.env.staging
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha f9ecf83f9402full audit observations/trust-audit/mcp-server/laigeoffer__pmhub.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-29f9ecf83f9402BLOCKF42first audit
06

Questions

What is the PmHub MCP server?

PmHub,一个基于 SpringCloud & LLM 的智能项目管理系统,该项目旨在帮助小伙伴们快速掌握微服务/分布式项目的架构设计和开发流程。如果你想在校招或者社招中拿到一个满意的 offer,PmHub 将是一个非常 nice 的选择😄。

What tools does PmHub expose?

200 in total: 405 read-only, 16 that write, and 7 that can delete or overwrite (always, caption, clear, column, inset). Every one is listed on this page with its risk.

Is PmHub safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (42/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does PmHub need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (f9ecf83f9402), read on 2026-09-29. The repository is watched and re-audited when it changes.

Advertisement