infisical-mcp-server — security grade SAFE, quality 71/100

Security audit verdict: SAFE · quality 71/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by Infisical · MCP Server · ★ 61

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is infisical-mcp-server safe to install? View the security audit →

About infisical-mcp-server

Infisical Model Context Protocol The Infisical Model Context Protocol server allows you to integrate with Infisical APIs through function calling. This protocol supports various tools to interact with Infisical. Setup Environment variables In order to use the MCP server, you must first set the environment variables required for authentication. : The authentication method to use. Supported values are and . Defaults to . : The Machine Identity universal auth client ID. Required when is . : The Machine Identity universal auth client secret. Required when is . : An access token for authentication. This can be both a personal access token or a machine identity access token. Required when is . : Optionally set a custom host URL. This is useful if you're self-hosting Infisical or you're on dedicated infrastructure. Defaults to . To run the Infisical MCP server using npx, use the following command: Usage with Claude Desktop Add the following to your . See here for more details. #

Quick Facts

Stars61
Forks20
LanguageTypeScript
CategoryMCP Server
LicenseApache-2.0
Quality Score71.1993501450632/100
Open Issues20
Last Updated2026-09-10
Created2025-04-11
Platformsmcp, node
Est. Tokens~9k

Compatible Skills

These tools work well together with infisical-mcp-server for enhanced workflows:

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is infisical-mcp-server?

infisical-mcp-server is Infisical's official MCP server.. It is categorized as a MCP Server with 61 GitHub stars.

What programming language is infisical-mcp-server written in?

infisical-mcp-server is primarily written in TypeScript.

How do I install or use infisical-mcp-server?

You can find installation instructions and usage details in the infisical-mcp-server GitHub repository at github.com/Infisical/infisical-mcp-server. The project has 61 stars and 20 forks, indicating an active community.

What license does infisical-mcp-server use?

infisical-mcp-server is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools