Atlas / MCP servers / mcpcat / MCPcat

MCPcatSAFE

mcp/mcpcat/mcpcat-1

AgentCat is an analytics platform for MCP server owners 🐱.

Verdict
SAFE
Grade
B
Trust score
87 /100
Exposed tools
62 55r · 7w · 0d
Transport
streamable-http
License
MIT
Stars
124
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Getting Started · Features · Docs · Website · Open Source · Schedule a Demo

[!NOTE] AgentCat v2 introduces compatibility with the MCP Protocol "Stateless" 2026-07-28 Update and the coinciding MCP TypeScript SDK v2 release that puts it into effect. The stateless transition has a massive impact on analytics, as sessions were a built-in concept tying related tool calls together. AgentCat has now migrated its ses
Read from source at commit be4f1e07912bOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add agentcat --env DD_API_KEY=${DD_API_KEY} --env DIAGNOSTICS_TOKEN=${DIAGNOSTICS_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "agentcat": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "DD_API_KEY": "${DD_API_KEY}",
        "DIAGNOSTICS_TOKEN": "${DIAGNOSTICS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (62)

55 read · 7 write · 0 destructive.

ToolRiskDescription
addwrite
add_notewrite
add_todowriteAdd a new todo item
add_with_descwriteAdds two numbers
barereadno schema
bigreadbig
bigintreadb
boomread
calculateread
calculator_addwrite
claims_keyreadalready declares the key
complete_todoread
composedreadcomposed
echoreadEcho a message back
eitherreadcomposed output
error_resultreadisError result
error_with_causereadThrows error with cause
existing_toolreadA tool with existing schema
exploderead
get_annotated_screenshotreadReturns a screenshot with annotations
get_attachmentreadReturns an image attachment
get_audio_clipreadReturns an audio clip
get_large_reportreadReturns a large report
get_more_toolsreadcustomer version
get_statsread
get_todo_screenshotreadReturns a screenshot of todos
get_verbose_logreadReturns a huge log dump
greetread
initial_toolread
late_exploderead
late_looseread
late_toolread
leakyread
list_todosreadList all todo items
looseread
my_toolreadDoes something useful
new_tool_after_trackreadA tool added after track() was called
noopread
optional_toolreadA tool with no required fields
own_handlesreaddeclares its own
poisonreadp
polyreadcomposed output schema
post_track_toolwriteA tool added after tracking was enabled
process_bulk_datareadProcesses a bulk data payload
recursivereadr
secret_echoreadechoes
simple_toolreadA simple tool
slow_echoreadechoes slowly
statsreadreturns stats
still_worksreadfixed reply
strictread
structuredread
structured_onlyreadstructured-only reply
test_context_removalreadTest tool that captures callback arguments
test_toolread
throw_stringreadThrows string
throwsreadthrows
token_probereadfixed reply
tool_with_contextreadA tool that already has context
type_error_toolreadThrows TypeError
union_toolreadtakes one of two shapes
upload_filewriteUpload a file as base64
04

Trust audit

SAFEgrade B · trust 87/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (21)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/tests/eventQueue.test.ts:502
const SECRET = "TOP_SECRET_PAYLOAD_abc123";
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.suspicious_name · CWE-1104
src/tests/diagnostics-no-payload.test.ts
diagnostics-no-payload.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/modules/diagnostics.ts:9
import packageJson from "../../package.json" with { type: "json" };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/modules/exporters/datadog.ts:1
import { Event, Exporter } from "../../types.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/modules/exporters/otlp.ts:1
import { Event, Exporter } from "../../types.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/modules/exporters/posthog.ts:2
import { Event, Exporter } from "../../types.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/modules/exporters/posthog.ts:6
import KSUID from "../../thirdparty/ksuid/index.js";
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
src/tests/compatibility.test.ts:85
it("logs a shape-fingerprint beacon when rejecting an unrecognized server shape", () => {
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
src/tests/compatibility.test.ts:98
const beacon = messages.find((m: string) =>
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
src/tests/compatibility.test.ts:101
expect(beacon).toBeDefined();
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
src/tests/compatibility.test.ts:102
expect(beacon).toContain("hasServerProp");
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
src/tests/compatibility.test.ts:103
expect(beacon).toContain(SUPPORT_MATRIX_SUFFIX);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/tests/e2e-http/lanes.ts:96
return { httpServer, baseUrl: `http://127.0.0.1:${port}/mcp` };
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/tests/e2e-http/sse-smoke-v1.test.ts:76
new URL(`http://127.0.0.1:${port}/mcp`),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/tests/e2e-http/sse-smoke-v2.test.ts:82
const baseUrl = `http://127.0.0.1:${port}/mcp`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/tests/engine-callwrap.test.ts:317
req: new Request("http://127.0.0.1:4105/mcp", {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/tests/engine-callwrap.test.ts:328
expect(extra.http.req.url).toBe("http://127.0.0.1:4105/mcp");
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@cloudflare/vitest-pool-workers, @cloudflare/workers-types, @modelcontextprotocol/client, @modelcontextprotocol/node, @modelcontextprotocol/sdk, @modelcontextprotocol/server, @types/node, @types/uuid
Why it matters. 21 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
docs/cats/bibi.png
docs/cats/bibi.png
Why it matters. 2913451 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/cats/void.jpg
docs/cats/void.jpg
Why it matters. 6011875 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha be4f1e07912bfull audit observations/trust-audit/mcp-server/mcpcat__mcpcat-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07be4f1e07912bSAFEB87first audit
06

Questions

What is the MCPcat MCP server?

AgentCat is an analytics platform for MCP server owners 🐱.

What tools does MCPcat expose?

62 in total: 55 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is MCPcat safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (87/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does MCPcat need?

It reads DD_API_KEY and DIAGNOSTICS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does MCPcat run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as agentcat at 2.1.1.

How current is this page?

The grade is for one exact copy of the source (be4f1e07912b), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement