MCP spec 2026-07-28 goes final: 10,000+ servers must migrate. Time left: Check your server now →
Agent Tool Risk Report

huggingface.co

Generated by the Conformant public-subset battery and anchored to the Sigstore/Rekor transparency log. The grade below is tamper-evident: recompute the report’s canonical hash and compare it with the Rekor entry.

https://huggingface.co/mcp
huggingface.co/mcp · public-subset battery v2.0.0 · Fri, 14 Aug 2026 07:38:22 GMT · report 8e2ab4eebdd3ffd2
B
Overall B (88/100). Connect with standard review: minor findings to track.
Second axis · not part of the grade

Spec 2026-07-28 readiness

NOT OBSERVABLE

Not determinable from the public probe. Credential-gated endpoints do not complete an unauthenticated handshake, so the negotiated revision cannot be read. This is a coverage limit, not a finding.

3 of 6 signals evaluable on the public probe · deprecation windows close 2027-07-28
  • RDY-01Transport generationcurrent
    Streamable HTTP: the transport the 2026-07-28 stateless core is built on.
  • RDY-02Protocol revisionn/a
    Revision negotiation could not be observed.
  • RDY-03Stateless corepartial
    Issues Mcp-Session-Id. Sessions remain valid under 2026-07-28, but the stateless core no longer requires them; confirm session loss is handled gracefully.
  • RDY-04Client registrationcurrent
    Advertises Client ID Metadata Document support, the 2026-07-28 replacement for Dynamic Client Registration.
  • RDY-05Cacheable tool catalogn/a
    Tool catalog cache posture not observable.
  • RDY-06Deprecated capabilitiesn/a
    Capability set not observable.

Readiness measures migration posture against the specification finalized 2026-07-28. It is reported separately because a well-authenticated server on deprecated transport is a migration risk, not a security defect — scoring both on one axis would misprice both. Signals that could not be evaluated are excluded from the score rather than counted as passing.

CFM-01AuthenticationWARN
Anonymous by design: every exposed tool is read-only.
  • Open endpoint, read-only surface. The server completes initialize and lists tools without credentials, but all exposed tools are read-only. Acceptable for public-data servers; confirm no tenant-scoped data is reachable.
CFM-02Authorization (OAuth)N/A
No authentication layer present to evaluate (see CFM-01).
CFM-03Tool poisoningPASS
1 suspicious pattern(s) detected across the tool surface.
  • Oversized description. tool "hf_fs" is 2789 characters; large descriptions are a common carrier for embedded instructions.
CFM-04Scopes & least privilegeWARN
1 over-privilege signal(s) on the tool surface.
  • Arbitrary-execution parameter. tool "hf_fs" accepts a raw execution parameter (cmd); the tool's effective scope is whatever the backing system allows.
CFM-05Secrets exposurePASS
No credential patterns in disclosed tool definitions or instructions.
CFM-06Destructive-tool guardrailsPASS
No destructive-class tools exposed.
CFM-08Transport securityPASS
TLS transport.
CFM-10Exposed configuration surfacePASS
No configuration or credential documents served at well-known paths.
CFM-09Command-injection exposure (advisory)INFO
1 command-execution sink(s) observed: the class OX Security's MCP command-injection (2026-04-15) targets. Local STDIO config-injection families are attested via Cleared-to-Connect, not remotely tested.
  • Command-execution sink: tool "hf_fs". Accepts a command-shaped parameter (cmd, args): the sink OX Security's MCP command-injection class ultimately targets. Confirm inputs are validated and never shelled out unsanitized.
✔ anchoredsha256:8e2ab4eebdd38794d3→ Sigstore/Rekor logIndex 2463222534verify ↗tamper-evident · independently checkable

Embed this grade

The badge URL is stable per server: weekly re-verification updates the grade and date in place. It links to this live anchored report.

Conformant badge for https://huggingface.co/mcp
<a href="https://conformant.io/report/8e2ab4eebdd3ffd2" target="_blank" rel="noopener">
  <img src="https://conformant.io/api/badge?server=https%3A%2F%2Fhuggingface.co%2Fmcp" alt="Conformant security grade" width="232" height="44" />
</a>