← Back to search Server uses network capabilities via: fetch(), https Server uses filesystem capabilities via: fs, fs sync ops, open(), os, path, pathlib Server uses shell capabilities via: child_process, spawn(), subprocess Server uses env_vars capabilities via: os.environ, process.env
ControlKeel
Governed MCP workflows with policy validation, findings tracking, and review gates.
? Not scanned yet
Versions
0.2.29latestfirst seen May 19, 2026
Tools 0
No tools indexed yet.
Permissions 4
network medium filesystem low shell high env_vars low Scan Findings 18
medium
OAuth implementation without PKCE
info
Sandbox failed to start for behavioral verification
info
package.json metadata
info
Required env vars (5)
info
Sandbox failed to start for output poisoning scan
medium
Permission: network access detected
low
Permission: filesystem access detected
high
Permission: shell access detected
low
Permission: env_vars access detected
info
SBOM generated: 1 components
critical
Database URL with Password found in aryaminus-controlkeel-d566562/docker-cloud-compose.yml
critical
Database URL with Password found in aryaminus-controlkeel-d566562/priv/benchmarks/benign_baseline_v1.json
critical
AWS Access Key ID found in aryaminus-controlkeel-d566562/priv/benchmarks/vibe_failures_v1.json
critical
Database URL with Password found in aryaminus-controlkeel-d566562/priv/benchmarks/vibe_failures_v1.json
critical
Database URL with Password found in aryaminus-controlkeel-d566562/.github/workflows/ci.yml
critical
AWS Access Key ID found in aryaminus-controlkeel-d566562/lib/controlkeel/cloud/eval_runner.ex
critical
Database URL with Password found in aryaminus-controlkeel-d566562/lib/controlkeel/ops/deployment_advisor.ex
medium
No build provenance detected (SLSA L0)