PkgRadar

PyPI · pypi.org

mcp-server-motherduck

Credential file access: matched "aws_access_key"

Why PkgRadar flagged 1.0.7

SeveritySignalEvidence
mediumCredential file accessmatched "aws_access_key" · mcp_server_motherduck-1.0.7/src/mcp_server_motherduck/database.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.7Review62026-06-09

Block this in CI

PkgRadar gates mcp-server-motherduck (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi mcp-server-motherduck==1.0.7