Independent MCP server safety profile · methodology
npm i)YES — runs arbitrary codeGET /mcp/verify?package=%40jmrgrav%2Fmcp-hugo-server-go. See the whole ecosystem in the State of MCP Security report, or browse all audited servers.GET /mcp/drift.json?packages=@jmrgrav/mcp-hugo-server-goНЕ ставить без ревью исходника: опасные признаки. Data from PulseFeed's independent MCP audit (last crawl 2026-08-25). An install script is not automatically malicious — native builds use them — but each is an unreviewed code-execution vector worth checking. All audited MCP servers →