md-to-pdf

clawhub:md-to-pdf

View source
B
85/100

First Seen

Feb 18, 2026

Last Scanned

Feb 20, 2026

Findings

1

Score

85/100

HIGH 1

Findings (1)

HIGH
Shell metacharacters in MCP config args
L110

Detects shell metacharacters (pipes, backticks, subshells) in MCP server command arguments

"args":["--no-sandbox"]}'`
FIX

Remove credentials (API keys, tokens, passwords) from MCP server configuration. Use environment variable references (e.g., ${API_KEY}) or a secrets manager instead of inline values.

FP?

Likely FP if the credential value is a placeholder (e.g., your-api-key-here, sk_test_xxx) in example configuration.