Synter Mcp Server— mcp server

Synter Mcp Server — independently scanned and version-tracked by SaferSkills.

by jshorwitz·MCP Server·github.com/jshorwitz/synter-mcp-server

Is Synter Mcp Server safe to install?

SaferSkills independently audited Synter Mcp Server (MCP Server) and scored it 15/100 (red). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.

Score
15/100
●●○○○○○○○○
↑ +0 since first scan (15 → 15)Re-scan~30s
Latest scan
ScannedJun 24, 2026 · 31d ago
Scans run1 over 90 days
Detectors55 checks · 5 categories
Findings0 warnings · 1 high
EngineSaferSkills 2b638c6
View methodology →
SaferSkills installs
This week0
This month0
All time0
CategoryWeightCategory scoreContribution
Securityprompt, exec, net, exfil, eval
35%
20
7.0 pts
Supply chainhash, typosquat, maintainer, lockfile
20%
100
20.0 pts
Maintenancestaleness, pinning, CI
15%
100
15.0 pts
TransparencySKILL.md, perms, README
15%
100
15.0 pts
Communityinstalls, verify, response
15%
100
15.0 pts

Findings & checks · 1 flagged

Securityscore 20 · 1 finding
CRITICALHidden-looking MCP tool name signals a shadow toolSS-MCP-POISON-SHADOW-TOOL-01 · Tool poisoning · manifest.json
CRITICALA shadow tool can perform arbitrary tool actions while appearing benign in manifest review.
Why it matters

This server publishes a tool whose name ({match}) uses an "internal/private" naming convention. The agent still sees and may invoke it, but a human reviewing the manifest skips over names that visually signal "not for me" — letting a hidden tool act unreviewed.

The exact value spotted
excerptmanifest.json· json
42{"name": "create_display_campaign", "description": "Create a Google Display campaign with re
… (23 chars elided on L42)
43{"name": "create_pmax_campaign", "description": "Create a Performance Max campaign across al
… (20 chars elided on L43)
44{"name": "create_meta_campaign", "description": "Create a Facebook/Instagram campaign"},
45{"name": "create_linkedin_campaign", "description": "Create a LinkedIn campaign for B2B adve
… (10 chars elided on L45)
46{"name": "create_reddit_campaign", "description": "Create a Reddit campaign for community-ba
… (18 chars elided on L46)
Occurrences
1 occurrence · at L44
How to fix
Rename internal-looking tools to plainly describe their purpose, or remove them if not consumer-facing.
  1. Confirm whether the flagged tool is meant to be reachable by the consuming agent.
  2. If it is, give it a clear descriptive name; if it is not, remove it from the manifest.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-MCP-POISON-SHADOW-TOOL-01sha256586b06a3c91937d8rubric 365aacaView on GitHub
Supply chainscore 100 · 0 findings
All supply chain checks passedNo findings in this category for the latest scan.pass
Maintenancescore 100 · 0 findings
All maintenance checks passedNo findings in this category for the latest scan.pass
Transparencyscore 100 · 0 findings
All transparency checks passedNo findings in this category for the latest scan.pass
Communityscore 100 · 0 findings
All community checks passedNo findings in this category for the latest scan.pass
Vendor response · right of reply
Are you the maintainer? Submit a response →

Audit the pieces. Scan the whole. Decide.

~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.