#1761·SurfSense

MCP server audit: 65 tools, 95%/A quality, 97%/A security

Author: vishalhabib99Created Sep 9, 2026Updated Sep 10, 2026

MCP server audit: 65 tools, 95%/A quality, 97%/A security

Ran mcp-doctor (a static analyzer for MCP server implementations — missing tool descriptions, unhandled errors, dangerous dynamic execution, SSRF-prone requests, hardcoded secrets) against SurfSense's MCP server. Sharing the result since it's a clean one and might be useful context if you ever want a second opinion on the MCP surface specifically (not the rest of the platform).

65 tools detected, 95%/A quality, 97%/A security.

A couple of honest caveats on the scan itself, not findings about your code:

  • 10 files under surfsense_backend/ were skipped (parser limitation on this analyzer's side, not a syntax problem in your code) — the scores above are accurate for everything that was parsed, just not a claim of 100% file coverage.
  • This only covers the literal MCP tool surface — SurfSense is obviously a much bigger platform than that.

No action needed from this — just wanted to share since the number came out genuinely good and I know some maintainers like having an outside data point. Happy to answer anything about the methodology.