No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by 1Panel-dev · MCP Server · ★ 164
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is mcp-1panel safe to install? View the security audit →
1Panel MCP Server 1Panel MCP Server is an implementation of the Model Context Protocol (MCP) server for 1Panel. Installation Prerequisites Go 1.25.0 or higher Existing 1Panel Build from Source Clone the repository: Build the project: Move to the system environment path. Install using go install Usage Cursor and Windsurf configuration example: stdio mode Streamable HTTP with standalone TLS can create and persist its own local CA and HTTPS server certificate. It does not depend on 1Panel certificate management. On first startup, the server writes the CA path and SHA-256 fingerprint to stderr. Configure the MCP client to trust the generated ; do not disable certificate verification. The CA is reu
| Stars | 164 |
| Forks | 27 |
| Language | Go |
| Category | MCP Server |
| License | GPL-3.0 |
| Quality Score | 79.8674952288577/100 |
| Open Issues | 1 |
| Last Updated | 2026-08-14 |
| Created | 2025-03-18 |
| Platforms | go, mcp |
| Est. Tokens | ~9k |
These tools work well together with mcp-1panel for enhanced workflows:
Explore other popular mcp server tools:
mcp-1panel is mcp-1panel is an implementation of the Model Context Protocol (MCP) server for 1Panel.. It is categorized as a MCP Server with 164 GitHub stars.
mcp-1panel is primarily written in Go. It covers topics such as 1panel, mcp, mcp-server.
You can find installation instructions and usage details in the mcp-1panel GitHub repository at github.com/1Panel-dev/mcp-1panel. The project has 164 stars and 27 forks, indicating an active community.
mcp-1panel is released under the GPL-3.0 license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: