Atlas / MCP servers / reshaprio / Reshapr

ReshaprBLOCK

mcp/reshaprio/reshapr

The open source, no-code MCP Server for AI-Native API Access

Verdict
BLOCK
Grade
F
Trust score
56 /100
Exposed tools
2 2r · 0w · 0d
Transport
—
License
Apache-2.0
Stars
128
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/reshaprio/reshapr/actions) [](https://quay.io/repository/reshapr/reshapr-ctrl?tab=tags) []((https://central.sonatype.com/search?q=io.reshapr)) [](https://www.npmjs.com/package/@reshapr/reshapr-cli) [](https://www.npmjs.com/package/@reshapr/reshapr-cli) [](https://www.apache.org/licenses/LICENSE-2.0) [](https://discord.gg/KyDUdam34h) [](https://github.com/reshaprio/reshapr) [](https://github.com/reshaprio/reshapr/forks)

**Website** | **About** | **Docs** | **Blog** | **Community**

✨ What is reShapr?

reShapr is the open source, no-code MCP Server for AI-Native API Access. It bridges the gap between traditional REST/

Read from source at commit 13b72cb98ddcOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add reshapr-web-ui --env RESHAPR_ADMIN_API_KEY=${RESHAPR_ADMIN_API_KEY} -- npx -y @reshapr/[email protected]
claude-desktop
{
  "mcpServers": {
    "reshapr-web-ui": {
      "command": "npx",
      "args": [
        "-y",
        "@reshapr/[email protected]"
      ],
      "env": {
        "RESHAPR_ADMIN_API_KEY": "${RESHAPR_ADMIN_API_KEY}"
      }
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
acmereadAcme organization
e2eorgreadOrganization for E2E tests
04

Trust audit

BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
control-plane/src/main/resources/keys/jwt-rs256.pem:1
-----BEGIN PRIVATE KEY-----
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
cli/src/commands/login.ts:33
.option('-k, --insecure', 'Skip SSL certificate validation')
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMInventory / provenance · inv.binary · CWE-1104
.mvn/wrapper/maven-wrapper.jar
maven-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
api/.mvn/wrapper/maven-wrapper.jar
maven-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
commons/.mvn/wrapper/maven-wrapper.jar
maven-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
control-plane/.mvn/wrapper/maven-wrapper.jar
maven-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli/src/cli.ts:42
Logger.warn(`Your token has expired. Please login again using the \`${CLI_NAME} login\` command.`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli/src/commands/api-token.ts:90
Logger.error(`Creating API token failed: ${response.statusText}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli/src/commands/api-token.ts:101
Logger.warn(`The API Token to register Gateway is: ${token.organizationId}-${token.token}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli/src/commands/api-token.ts:132
Logger.error(`Failed to delete API token: ${response.statusText}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli/src/commands/api-token.ts:136
Logger.info(`API token with ID ${tokenId} deleted successfully.`);
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
control-plane/src/main/resources/application.properties:105
reshapr.ctrl.api.key=${RESHAPR_CTRL_API_KEY:CzBuQ9B0i8qrUQe6WLiDLqR3gv4iCbxvjTJQP0z0CFGQbjgBHPZSusa9d1gZKwwjdoCsJ8ogRwRzc06GipJSjSDkFOy0BSOKvAa2EjU3As9I5UjgizTzxsJAVJIXtdo2xiXHhcry9KeJa0zRhDtGmm8WMujo
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
install/create-admin.sh:29
SERVER_TOKEN=CzBuQ9B0i8qrUQe6WLiDLqR3gv4iCbxvjTJQP0z0CFGQbjgBHPZSusa9d1gZKwwjdoCsJ8ogRwRzc06GipJSjSDkFOy0BSOKvAa2EjU3As9I5UjgizTzxsJAVJIXtdo2xiXHhcry9KeJa0zRhDtGmm8WMujoXrlfj0ChlJKaHZiZsRthd4UHrWkKur9
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
install/create-service-account.sh:27
SERVER_TOKEN=CzBuQ9B0i8qrUQe6WLiDLqR3gv4iCbxvjTJQP0z0CFGQbjgBHPZSusa9d1gZKwwjdoCsJ8ogRwRzc06GipJSjSDkFOy0BSOKvAa2EjU3As9I5UjgizTzxsJAVJIXtdo2xiXHhcry9KeJa0zRhDtGmm8WMujoXrlfj0ChlJKaHZiZsRthd4UHrWkKur9
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
install/create-user+org.sh:29
SERVER_TOKEN=CzBuQ9B0i8qrUQe6WLiDLqR3gv4iCbxvjTJQP0z0CFGQbjgBHPZSusa9d1gZKwwjdoCsJ8ogRwRzc06GipJSjSDkFOy0BSOKvAa2EjU3As9I5UjgizTzxsJAVJIXtdo2xiXHhcry9KeJa0zRhDtGmm8WMujoXrlfj0ChlJKaHZiZsRthd4UHrWkKur9
LOWInventory / provenance · inv.binary · CWE-1104
benchmarks/.mvn/wrapper/maven-wrapper.jar
maven-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/e2e/helpers/cli-runner.ts:21
const CLI_ENTRY = path.resolve(import.meta.dirname, '../../dist/cli.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/e2e/helpers/setup.ts:19
const COMPOSE_FILE = path.resolve(import.meta.dirname, '../../../install/docker-compose-all-in-one.yml');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/e2e/scenarios/import-and-expose-basic.e2e.test.ts:23
const OPEN_METEO_SPEC = path.resolve(import.meta.dirname, '../../../dev/open-meteo-openapi.yml');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/src/commands/admin/encryption.ts:17
import { Context } from '../../utils/context.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/src/commands/admin/encryption.ts:18
import { Logger } from '../../utils/logger.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
benchmarks/src/main/java/io/reshapr/benchmarks/e2e/E2EBenchEnvironment.java:138
.setBackendEndpoint("http://127.0.0.1:" + bench.backendPort())
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
benchmarks/src/main/java/io/reshapr/benchmarks/e2e/E2EGraphQLBenchEnvironment.java:140
.setBackendEndpoint("http://127.0.0.1:" + bench.backendPort())
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
benchmarks/src/main/java/io/reshapr/benchmarks/e2e/E2EGrpcBenchEnvironment.java:154
.setBackendEndpoint("http://127.0.0.1:" + backendPort)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
benchmarks/src/main/java/io/reshapr/benchmarks/proxy/ProxyServiceCallBackendBenchmark.java:111
backendUri = URI.create("http://127.0.0.1:" + backend.port() + "/api/bench");

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 13b72cb98ddcfull audit observations/trust-audit/mcp-server/reshaprio__reshapr.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0713b72cb98ddcBLOCKF56first audit
06

Questions

What is the Reshapr MCP server?

The open source, no-code MCP Server for AI-Native API Access

What tools does Reshapr expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Reshapr safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (56/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Reshapr need?

It reads RESHAPR_ADMIN_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (13b72cb98ddc), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement