No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by opentofu · MCP Server · ★ 108
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is opentofu-mcp-server safe to install? View the security audit →
OpenTofu MCP Server A Model Context Protocol (MCP) server for accessing the OpenTofu Registry. This server allows language model assistants to search for and retrieve information about OpenTofu providers, modules, resources, and data sources. Available as both a local Node.js server and a remote Cloudflare Worker deployment. Features Search the OpenTofu Registry for providers, modules, resources, and data sources Get detailed information about specific providers and modules Access documentation for resources and data sources Retrieve comprehensive OpenTofu configuration examples MCP-compatible interface for AI assistants Installation You can use this MCP server with any AI assistant that supports the Model Context Protocol. Choose between the hosted service or local installation: Hosted Service (Recommended) The easiest way to get started is to use our hosted service at .
| Stars | 108 |
| Forks | 6 |
| Language | TypeScript |
| Category | MCP Server |
| Quality Score | 66.0157991867281/100 |
| Last Updated | 2026-09-04 |
| Created | 2025-05-22 |
| Platforms | mcp, node |
| Est. Tokens | ~14k |
Explore other popular mcp server tools:
opentofu-mcp-server is OpenTofu MCP Server for accessing the OpenTofu Registry. It is categorized as a MCP Server with 108 GitHub stars.
opentofu-mcp-server is primarily written in TypeScript.
You can find installation instructions and usage details in the opentofu-mcp-server GitHub repository at github.com/opentofu/opentofu-mcp-server. The project has 108 stars and 6 forks, indicating an active community.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: