No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by alkoleft · MCP Server · ★ 105
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is mcp-onec-test-runner safe to install? View the security audit →
METR - MCP 1C:Enterprise Test Runner  и запуска тестов YaXUnit в проектах 1С:Предприятие из AI‑ассистентов (Claude, GPT, VS Code и др.).. It is categorized as a MCP Server with 105 GitHub stars.
mcp-onec-test-runner is primarily written in Kotlin.
You can find installation instructions and usage details in the mcp-onec-test-runner GitHub repository at github.com/alkoleft/mcp-onec-test-runner. The project has 105 stars and 21 forks, indicating an active community.
mcp-onec-test-runner is released under the GPL-3.0 license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: