MaggBLOCK
Magg: The MCP Aggregator
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[//]: # ([](https://github.com/sitbon/magg/actions/workflows/test.yml)) [](https://pypi.org/project/magg/) [](https://pypi.org/project/magg/) [](https://github.com/sitbon/magg/releases) [](https://deepwiki
c3af199dcc9bOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add magg -- uvx magg==1.3.0 serve
Exposed tools (6)
4 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add | write | Add two numbers. |
delegate_test | read | A tool that could be delegated to. |
echo | read | return f |
multiply | read | Multiply two numbers. |
test_add | write | return f |
test_tool | read | return f |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (10)
exec(startup_code, self.console.locals)
auth_init.add_argument("--key-path", type=Path, help="Path for authentication keys (default: ~/.ssh/magg)")print(token)
print(f"export MAGG_JWT={token}")export MAGG_PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----\nMIIE..."
print(f"Using MaggClient{' with provided token' if args.token else f' (loading from {args.env_var})'}")[.decode("utf-8")return data.text if hasattr(data, "text") else base64.b64decode(data.blob)
-e MAGG_PRIVATE_KEY="$(cat ~/.ssh/magg/magg.key)" \
Gates applied: no_behavioural_pass.
c3af199dcc9bfull audit observations/trust-audit/mcp-server/sitbon__magg.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | c3af199dcc9b | BLOCK | D | 69 | first audit |
Questions
What is the Magg MCP server?
Magg: The MCP Aggregator
What tools does Magg expose?
6 in total: 4 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Magg safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Magg need?
It reads MAGG_PRIVATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Magg run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as magg.
How current is this page?
The grade is for one exact copy of the source (c3af199dcc9b), read on 2026-10-07. The repository is watched and re-audited when it changes.