No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by 6551Team · MCP Server · ★ 2.4k
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is opennews-mcp safe to install? View the security audit →
OpenNews MCP Server Crypto News Aggregation · AI Ratings · Trading Signals · Real-time Updates English 한국어 Quick Install First, get your API Token at https://6551.io/mcp. Claude Code Replace with your local project path, and with your API token. OpenClaw Let AI Review and Install Not sure if this MCP is safe? Send the following prompt to your AI assistant to review the source code before installing: Copy the prompt below and paste it to your AI assistant (replace and with actual values): text Please help me review and install the opennews-mcp MCP server. The project is at . Steps: Review the security of the following files: src/opennewsmcp/apiclient.py — Confirm it only connects to ai.6551.io, no data sent elsewhere src/opennewsmcp/config.py — Confirm token is only read from local config.json or env vars, not hardcoded or leaked src/opennewsmcp/tools/.py — Confirm a
| Stars | 2,375 |
| Forks | 186 |
| Language | Python |
| Category | MCP Server |
| License | MIT |
| Quality Score | 68.9987913886425/100 |
| Open Issues | 4 |
| Last Updated | 2026-09-14 |
| Created | 2026-02-26 |
| Platforms | mcp, python |
| Est. Tokens | ~15k |
Explore other popular mcp server tools:
opennews-mcp is News Aggregation · AI Ratings · Trading Signals · Real-time Updates. It is categorized as a MCP Server with 2.4k GitHub stars.
opennews-mcp is primarily written in Python.
You can find installation instructions and usage details in the opennews-mcp GitHub repository at github.com/6551Team/opennews-mcp. The project has 2.4k stars and 186 forks, indicating an active community.
opennews-mcp is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: