THRONE
See report Verify server

registry / record

github.com/googleapis/mcp-toolbox

github / sealed 2026-06-12 / No. 369e3886

> throne registry github.com/googleapis/mcp-toolbox sealed
This target couldn't be started as an MCP serverno package.json or pyproject.toml at the repository root — Throne can launch Node (npm/pnpm/yarn) and Python (uv) projects
receiptsealed evidence
scan id
369e3886ea744501bbbda7b6f44e41d3
target
https://github.com/googleapis/mcp-toolbox
sealed at
2026-06-12 06:57:32Z
evidence hash
sha256:24695a1a9ae229dbc36a6c0fbc84d35d43db56515622e7e67e2aca4c4aae7870
01connectFAIL0ms

server never launched: no package.json or pyproject.toml at the repository root — Throne can launch Node (npm/pnpm/yarn) and Python (uv) projects

02discoverSKIPPED0ms

not run — server never launched

03validate_schemasSKIPPED0ms

not run — server never launched

04smoke_test_toolsSKIPPED0ms

not run — server never launched

05error_handlingSKIPPED0ms

not run — server never launched

06streamingSKIPPED0ms

not run — server never launched

07resource_lifecycleSKIPPED0ms

not run — server never launched

08concurrent_callsSKIPPED0ms

not run — server never launched

09reconnectSKIPPED0ms

not run — server never launched

01connectFAIL0ms

server never launched: no package.json or pyproject.toml at the repository root — Throne can launch Node (npm/pnpm/yarn) and Python (uv) projects

02discoverSKIPPED0ms

not run — server never launched

03validate_schemasSKIPPED0ms

not run — server never launched

04smoke_test_toolsSKIPPED0ms

not run — server never launched

05error_handlingSKIPPED0ms

not run — server never launched

06streamingSKIPPED0ms

not run — server never launched

07resource_lifecycleSKIPPED0ms

not run — server never launched

08concurrent_callsSKIPPED0ms

not run — server never launched

09reconnectSKIPPED0ms

not run — server never launched

chatgpt desktopemulation profile pending real-traffic captureCOMING SOON
SECURITY: REVIEW / 41 finding(s), 4 high / review material, not a verdict
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value opaq… (23 chars) — verify it is not a live credential

mcp-toolbox-HEAD/internal/auth/generic/generic_test.go:345
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value opaq… (19 chars) — verify it is not a live credential

mcp-toolbox-HEAD/internal/auth/generic/generic_test.go:360
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value opaq… (22 chars) — verify it is not a live credential

mcp-toolbox-HEAD/internal/auth/generic/generic_test.go:378
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value opaq… (21 chars) — verify it is not a live credential

mcp-toolbox-HEAD/internal/auth/generic/generic_test.go:404
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value opaq… (16 chars) — verify it is not a live credential

mcp-toolbox-HEAD/internal/auth/generic/generic_test.go:415
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value opaq… (18 chars) — verify it is not a live credential

mcp-toolbox-HEAD/internal/auth/generic/generic_test.go:455
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value opaq… (23 chars) — verify it is not a live credential

mcp-toolbox-HEAD/internal/auth/generic/generic_test.go:708
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value opaq… (19 chars) — verify it is not a live credential

mcp-toolbox-HEAD/internal/auth/generic/generic_test.go:723
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value opaq… (22 chars) — verify it is not a live credential

mcp-toolbox-HEAD/internal/auth/generic/generic_test.go:741
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value opaq… (21 chars) — verify it is not a live credential

mcp-toolbox-HEAD/internal/auth/generic/generic_test.go:767
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value opaq… (16 chars) — verify it is not a live credential

mcp-toolbox-HEAD/internal/auth/generic/generic_test.go:778
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value opaq… (18 chars) — verify it is not a live credential

mcp-toolbox-HEAD/internal/auth/generic/generic_test.go:818
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value this… (23 chars) — verify it is not a live credential

mcp-toolbox-HEAD/tests/auth/auth_integration_test.go:209
LOWTHR-INSTALL-03 / Install-time script execution (npm lifecycle)

"prepack" runs on git-dependency installs and local dev (not registry installs): 'node scripts/downloadBinary.js darwin arm64'

mcp-toolbox-HEAD/npm/server-darwin-arm64/package.json
LOWTHR-INSTALL-03 / Install-time script execution (npm lifecycle)

"prepack" runs on git-dependency installs and local dev (not registry installs): 'node scripts/downloadBinary.js darwin x64'

mcp-toolbox-HEAD/npm/server-darwin-x64/package.json
LOWTHR-INSTALL-03 / Install-time script execution (npm lifecycle)

"prepack" runs on git-dependency installs and local dev (not registry installs): 'node scripts/downloadBinary.js linux x64'

mcp-toolbox-HEAD/npm/server-linux-x64/package.json
LOWTHR-INSTALL-03 / Install-time script execution (npm lifecycle)

"prepack" runs on git-dependency installs and local dev (not registry installs): 'node scripts/downloadBinary.js win32 arm64'

mcp-toolbox-HEAD/npm/server-win32-arm64/package.json
LOWTHR-INSTALL-03 / Install-time script execution (npm lifecycle)

"prepack" runs on git-dependency installs and local dev (not registry installs): 'node scripts/downloadBinary.js win32 x64'

mcp-toolbox-HEAD/npm/server-win32-x64/package.json
HIGHTHR-EXEC-04 / Arbitrary command execution from tool arguments

spawn() called with a dynamically built command (heuristic — review): "command, npxArgs, { shell: os.platform() === 'win32', stdio: 'inherit', env });"

mcp-toolbox-HEAD/cmd/internal/skills/generator.go:197
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

execSync() called with a dynamically built command (heuristic — review): "checkCommand, { stdio: 'pipe', encoding: 'utf-8' }).trim();"

mcp-toolbox-HEAD/cmd/internal/skills/generator.go:209
HIGHTHR-EXEC-04 / Arbitrary command execution from tool arguments

spawn() called with a dynamically built command (heuristic — review): "toolboxBinary, toolboxArgs, { stdio: 'inherit', env });"

mcp-toolbox-HEAD/cmd/internal/skills/generator.go:228
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

execSync() called with a dynamically built command (heuristic — review): '`xattr -d com.apple.quarantine "${binPath}"`, { stdio: \'ignore\' });'

mcp-toolbox-HEAD/npm/server/bin/run.js:40
HIGHTHR-EXEC-04 / Arbitrary command execution from tool arguments

spawn() called with a dynamically built command (heuristic — review): "binPath, process.argv.slice(2), { stdio: 'inherit' })"

mcp-toolbox-HEAD/npm/server/bin/run.js:49
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

execSync() called with a dynamically built command (heuristic — review): '`chmod +x "${destPath}"`);'

mcp-toolbox-HEAD/npm/server-darwin-arm64/scripts/downloadBinary.js:73
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

execSync() called with a dynamically built command (heuristic — review): '`chmod +x "${destPath}"`);'

mcp-toolbox-HEAD/npm/server-darwin-x64/scripts/downloadBinary.js:73
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

execSync() called with a dynamically built command (heuristic — review): '`chmod +x "${destPath}"`);'

mcp-toolbox-HEAD/npm/server-linux-x64/scripts/downloadBinary.js:73
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

execSync() called with a dynamically built command (heuristic — review): '`chmod +x "${destPath}"`);'

mcp-toolbox-HEAD/npm/server-win32-arm64/scripts/downloadBinary.js:73
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

execSync() called with a dynamically built command (heuristic — review): '`chmod +x "${destPath}"`);'

mcp-toolbox-HEAD/npm/server-win32-x64/scripts/downloadBinary.js:73
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

system() called with a dynamically built command (heuristic — review): ')'

mcp-toolbox-HEAD/pypi/src/toolbox_server/main.py:10
HIGHTHR-EXEC-04 / Arbitrary command execution from tool arguments

subprocess.run() called with a dynamically built command (heuristic — review): '[binary_path] + sys.argv[1:])'

mcp-toolbox-HEAD/pypi/src/toolbox_server/main.py:40
LOWTHR-NET-05 / Hardcoded outbound endpoints

16 non-local endpoint host(s) referenced in code — verify each is expected for this server's purpose: accounts.google.com (mcp-toolbox-HEAD/internal/auth/google/google.go:112), alloydb.googleapis.com (mcp-toolbox-HEAD/internal/sources/alloydbadmin/alloydbadmin.go:94), cloud.google.com (mcp-toolbox-HEAD/internal/log/handler.go:137), console.cloud.google.com (mcp-toolbox-HEAD/internal/server/static/js/auth.js:135), datatracker.ietf.org (mcp-toolbox-HEAD/internal/server/prm.go:18), developers.google.com (mcp-toolbox-HEAD/internal/server/static/js/toolDisplay.js:515), geminidataanalytics.googleapis.com (mcp-toolbox-HEAD/internal/tools/bigquery/bigqueryconversationalanalytics/bigqueryconversationalanalytics.go:38), mcp-toolbox.dev (mcp-toolbox-HEAD/.hugo/static/js/custom-layout.js:116), monitoring.googleapis.com (mcp-toolbox-HEAD/internal/sources/cloudmonitoring/cloud_monitoring.go:86), oauth2.googleapis.com (mcp-toolbox-HEAD/internal/auth/google/google.go:174), opentelemetry.io (mcp-toolbox-HEAD/internal/server/mcp.go:725), sqladmin.googleapis.com (mcp-toolbox-HEAD/internal/sources/cloudsqladmin/cloud_sql_admin.go:103), storage.googleapis.com (mcp-toolbox-HEAD/.ci/generate_release_table.sh:42), www.apache.org (mcp-toolbox-HEAD/.ci/sample_tests/run_tests.sh:7), www.googleapis.com (mcp-toolbox-HEAD/internal/sources/bigquery/bigquery.go:48)

mcp-toolbox-HEAD/.ci/generate_release_table.sh:42
LOWTHR-VER-11 / Outdated MCP SDK or protocol version pin

obsolete protocol version string '2024-11-05' in source

mcp-toolbox-HEAD/internal/server/mcp/util/util.go:18
LOWTHR-VER-11 / Outdated MCP SDK or protocol version pin

obsolete protocol version string '2024-11-05' in source

mcp-toolbox-HEAD/internal/server/mcp.go:403
LOWTHR-VER-11 / Outdated MCP SDK or protocol version pin

obsolete protocol version string '2024-11-05' in source

mcp-toolbox-HEAD/internal/server/mcp_test.go:43
LOWTHR-VER-11 / Outdated MCP SDK or protocol version pin

obsolete protocol version string '2024-11-05' in source

mcp-toolbox-HEAD/tests/alloydb/alloydb_integration_test.go:124
LOWTHR-VER-11 / Outdated MCP SDK or protocol version pin

obsolete protocol version string '2024-11-05' in source

mcp-toolbox-HEAD/tests/alloydbainl/alloydb_ai_nl_integration_test.go:239
LOWTHR-VER-11 / Outdated MCP SDK or protocol version pin

obsolete protocol version string '2024-11-05' in source

mcp-toolbox-HEAD/tests/auth/auth_integration_test.go:310
LOWTHR-VER-11 / Outdated MCP SDK or protocol version pin

obsolete protocol version string '2024-11-05' in source

mcp-toolbox-HEAD/tests/cloudgda/cloud_gda_integration_test.go:188
LOWTHR-VER-11 / Outdated MCP SDK or protocol version pin

obsolete protocol version string '2024-11-05' in source

mcp-toolbox-HEAD/tests/embedding.go:104
LOWTHR-VER-11 / Outdated MCP SDK or protocol version pin

obsolete protocol version string '2024-11-05' in source

mcp-toolbox-HEAD/tests/firestore/firestore_integration_test.go:375
LOWTHR-VER-11 / Outdated MCP SDK or protocol version pin

obsolete protocol version string '2024-11-05' in source

mcp-toolbox-HEAD/tests/tool.go:976
VERDICT: INCONCLUSIVESANDBOXED RUN — submitted server executed in a disposable microVM — compatibility not assessable: server never launched: no package.json or pyproject.toml at the repository root — Throne can launch Node (npm/pnpm/yarn) and Python (uv) projects / security: review — 41 finding(s), 4 highsealed by THRONE / No. 369e3886 / 2026-06-12
executed in a disposable microVM, created for this scan and destroyed after it. nothing outlives a run.

maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.

this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.