Caveat verdict
uumuse-brain
Knowledge base interface that routes to UUMuse MCP tools for searching and managing user-uploaded documents; no suspicious behavior, only instructs use of legitimate MCP tool calls.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (6)
Possible hardcoded credential
README.md · code · API_KEY="sk-uu-your-key
Social engineering — falsely claims user authorization
skill-card.md · prose · downgraded · the user has configured
HTTP request to bare IP address — common in malicious payloads
uumuse_mcp_stdio.py · prose · downgraded · http://192.168.4.58
Popular HTTP library — network access
README.md · prose · downgraded · got
Python urllib.request — network access
uumuse_mcp_stdio.py · prose · downgraded · urllib.request
Python os.environ.get — reads environment variable
uumuse_mcp_stdio.py · prose · downgraded · os.environ.get(
Permissions & capabilities
No declared permissions — minimal attack surface.
Is this flag fair?
Thanks — recorded.