ai.alpic.test/test-mcp-server

B
7.0

Alpic Test MCP Server - great server!

Installation

Claude Desktop config (remote)

{
  "mcpServers": {
    "ai-alpic-test-test-mcp-server": {
      "type": "streamable-http",
      "url": "https://test.alpic.ai/"
    }
  }
}

Cursor config

{
  "mcpServers": {
    "ai-alpic-test-test-mcp-server": {
      "url": "https://test.alpic.ai/"
    }
  }
}

Security Report

Score Breakdown

Description10
Permissions10
Behavior4
Stability--

Findings (6)

high
vague-description

Extremely vague server description

The description 'Alpic Test MCP Server - great server!' provides no meaningful information about what this server actually does, its capabilities, or its intended purpose. This is a major red flag for legitimacy and trustworthiness.

high
network-access

Remote HTTP endpoint without visible authentication

This server uses streamable-http transport with a remote URL (https://test.alpic.ai/), meaning it accepts connections from the internet. No authentication mechanism is documented.

medium
excessive-scope

No source code repository available

The server has no associated repository URL, making it impossible to audit the actual implementation, verify claims, or assess security practices.

medium
vague-description

Suspicious domain and naming pattern

The server name 'ai.alpic.test/test-mcp-server' combined with test domain 'test.alpic.ai' suggests this may be a test/development server, yet it's being presented as a production MCP server.

low
excessive-tools

Tool definitions unavailable for inspection

While the server reports 0 tools, tool definitions were not fetched, preventing verification of actual capabilities and potential security issues.

info
vague-description

Semantic Analysis Summary

This server presents significant security concerns due to its vague description, remote HTTP exposure without documented authentication, and complete lack of source code for verification. The test-domain naming and marketing-style description raise questions about legitimacy and production readiness. Recommend rejecting until proper documentation, authentication, and source code are provided.

Last scanned 1mo ago

Details

Version
0.0.1
Transport
streamable-http
Capabilities