Back to Browse

Pci Dss MCP Server

Developer ToolsUse Caution2.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Pci Dss MCP Server by MEOK AI Labs

About

Pci Dss MCP Server by MEOK AI Labs

Security Report

2.2
Use Caution2.2Critical Risk

This PCI DSS compliance MCP server has significant architectural and security concerns that warrant attention. The server implements read-only compliance assessment tools with reasonable input validation, but contains problematic patterns: (1) a remote metering/rate-limiting system that exfiltrates API keys to an external verification service, (2) environment variable exposure in error messages and return values, (3) an undefined external function call (_server_meter_check) that appears designed for telemetry, and (4) a fail-open authentication pattern that may hide licensing enforcement. While the core tools themselves are stateless and safe, the surrounding infrastructure creates data leakage and trust boundary issues. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 5 high severity). Package verification found 1 issue.

5 files analyzed · 15 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-csoai-org-pci-dss-mcp": {
      "args": [
        "pci-dss-mcp"
      ],
      "command": "uvx"
    }
  }
}

Reviews

No reviews yet

Be the first to review this server!