Atlas / MCP servers / sitbon / Magg

MaggBLOCK

mcp/sitbon/magg

Magg: The MCP Aggregator

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
6 4r · 2w · 0d
Transport
stdio · streamable-http
License
AGPL-3.0
Stars
144
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[//]: # ([![Tests](https://img.shields.io/github/actions/workflow/status/sitbon/magg/test.yml?style=flat-square&label=tests)](https://github.com/sitbon/magg/actions/workflows/test.yml)) [](https://pypi.org/project/magg/) [](https://pypi.org/project/magg/) [](https://github.com/sitbon/magg/releases) [](https://deepwiki

Read from source at commit c3af199dcc9bOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add magg -- uvx magg==1.3.0 serve
03

Exposed tools (6)

4 read · 2 write · 0 destructive.

ToolRiskDescription
addwriteAdd two numbers.
delegate_testreadA tool that could be delegated to.
echoreadreturn f
multiplyreadMultiply two numbers.
test_addwritereturn f
test_toolreadreturn f
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (7 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (10)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
magg/mbro/arepl.py:123
exec(startup_code, self.console.locals)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
magg/cli.py:1017
auth_init.add_argument("--key-path", type=Path, help="Path for authentication keys (default: ~/.ssh/magg)")
Why it matters. touches a credential store
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
magg/cli.py:813
print(token)
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
magg/cli.py:815
print(f"export MAGG_JWT={token}")
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/authentication.md:91
export MAGG_PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----\nMIIE..."
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
examples/authentication.py:36
print(f"Using MaggClient{' with provided token' if args.token else f' (loading from {args.env_var})'}")
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
readme.md:7
[![DeepWiki](https://img.shields.io/badge/DeepWiki-sitbon%2Fmagg-blue.svg?logo=data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACwAAAAyCAYAAAAnWDnqAAAAAXNSR0IArs4c6QAAA05JREFUaEPtmUtyEzEQhtWTQyQLHNak2AB
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
magg/discovery/metadata.py:288
content = base64.b64decode(data["content"]).decode("utf-8")
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
magg/util/transform.py:66
return data.text if hasattr(data, "text") else base64.b64decode(data.blob)
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
readme.md:113
-e MAGG_PRIVATE_KEY="$(cat ~/.ssh/magg/magg.key)" \
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha c3af199dcc9bfull audit observations/trust-audit/mcp-server/sitbon__magg.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07c3af199dcc9bBLOCKD69first audit
06

Questions

What is the Magg MCP server?

Magg: The MCP Aggregator

What tools does Magg expose?

6 in total: 4 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Magg safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Magg need?

It reads MAGG_PRIVATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Magg run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as magg.

How current is this page?

The grade is for one exact copy of the source (c3af199dcc9b), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement