mcp-feedback-enhanced — security grade SAFE, quality 67/100

Security audit verdict: SAFE · quality 67/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by Minidoracat · MCP Server · ★ 3.8k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is mcp-feedback-enhanced safe to install? View the security audit →

About mcp-feedback-enhanced

MCP Feedback Enhanced 🌐 Language / 語言切換: English 简体中文 Original Author: Fábio Ferreira | Original Project ⭐ Enhanced Fork: Minidoracat UI Design Reference: sanshao85/mcp-feedback-collector ## 📢 Maintenance Status (2026-08) The project is maintained again. Please upgrade to v2.6.1 — it fixes a command execution vulnerability: What changed in v2.6.1: - 🔒 Command execution removed — fixes #219 (unauthenticated WebSocket could execute arbitrary programs). The old blocklist only caught shell metacharacters, but since execution used metacharacters were never the risk — , , , passed straight through, and auto-command was enabled by default. The feature is gone for good. See SECURITY.md. - 🔒 Cross-Site WebSocket Hijacking fixed (reported privately as , ): browsers are not restricted by the same-origin policy when opening a WebSocket, so a malicious page could make your browser connect to the local . is now validated before , and cross-origin attempts are rejected

Quick Facts

Stars3,767
Forks349
LanguageJavaScript
CategoryMCP Server
Quality Score66.6611550711523/100
Open Issues8
Last Updated2026-09-07
Created2025-05-29
Platformsbrowser, mcp, node
Est. Tokens~18k

Compatible Skills

These tools work well together with mcp-feedback-enhanced for enhanced workflows:

  • ua-parser-js — semantic(0.20)+complementary+same_lang+similar_pop+shared_platform (57%)
  • paul — semantic(0.16)+complementary+same_lang+similar_pop+shared_platform (55%)
  • crystal — semantic(0.18)+complementary+similar_pop+shared_platform (46%)

mcp-feedback-enhanced alternative? Top 1 similar tools

Looking for a mcp-feedback-enhanced alternative? If you're comparing mcp-feedback-enhanced with other mcp server tools, these 1 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • mcp-for-beginners by microsoft · ⭐ 17.2k

    This open-source curriculum introduces the fundamentals of Model Context Protocol (MCP) through real-world, cr

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular JavaScript Agent Tools

Frequently Asked Questions

What is mcp-feedback-enhanced?

mcp-feedback-enhanced is Enhanced MCP server for interactive user feedback and command execution in AI-assisted development, featuring dual interface support (Web UI and Desktop Application) with intelligent environment detec. It is categorized as a MCP Server with 3.8k GitHub stars.

What programming language is mcp-feedback-enhanced written in?

mcp-feedback-enhanced is primarily written in JavaScript.

How do I install or use mcp-feedback-enhanced?

You can find installation instructions and usage details in the mcp-feedback-enhanced GitHub repository at github.com/Minidoracat/mcp-feedback-enhanced. The project has 3.8k stars and 349 forks, indicating an active community.

What are the best alternatives to mcp-feedback-enhanced?

The top alternatives to mcp-feedback-enhanced on Agent Skills Hub include mcp-for-beginners. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools