io.github.cyanheads
io.github.cyanheads/nhtsa-vehicle-safety-mcp-server
VOUCH79·BDecode VINs, search recalls, complaints, crash ratings, and investigations.
Trust report
Scanned 2026-08-05 · MCP 2025-11-25Scored by MCP Vouch against the OWASP MCP Top 10. SKIP applies to HTTP-only checks not relevant for stdio servers and is excluded from the score.
- PASSMCP01Tool Poisoning10 / 10
- WARNMCP02Insufficient Input Validation5 / 10
- SKIPMCP03Resource Injection—
- PASSMCP04Unauthorized Capability Exposure10 / 10
- WARNMCP05Missing Authentication5 / 10
- PASSMCP06Insecure Transport10 / 10
- PASSMCP07Shadow Tool Registration10 / 10
- PASSMCP08Lack of Audit and Telemetry10 / 10
- WARNMCP09Inadequate Rate Limiting5 / 10
- WARNMCP10Supply Chain Risk6 / 10
Is io.github.cyanheads/nhtsa-vehicle-safety-mcp-server safe to use?
io.github.cyanheads/nhtsa-vehicle-safety-mcp-server scores 79/100 — grade B, which is a solid posture with a few gaps worth reading. It passes 5 of the 9 OWASP MCP Top-10 checks that apply to it, with Insufficient Input Validation, Missing Authentication, Inadequate Rate Limiting, and Supply Chain Risk returning a warning rather than a pass. 1 further check does not apply to this server's transport and is excluded from the score entirely — skipped is not the same as failed. This is what the scanner found on 2026-08-05, not a guarantee. Re-run it yourself with `npx mcpr scan`.
What a grade B means, the ten checks behind it, and the point maths are all on how we score MCP server trust.
Slug
mcpr-io-github-cyanheads-nhtsa-vehicle-safety-mcp-server
License
Unspecified
Quality score
Not yet probed
Trust score
VOUCH79·B
Latest version
0.7.4
Published
2026-05-23
Homepage
—
Capabilities
Not yet declared in the manifest.
Embed the live badge
Always reflects the current grade. Score drops → badge drops. No vanity lock.
[](https://mcp-registry-dh5.pages.dev/servers/mcpr-io-github-cyanheads-nhtsa-vehicle-safety-mcp-server/)
Install
One-click cross-client install (Claude Code, Claude Desktop, Cursor, Windsurf) coming soon. The registry will write the correct config fragment to the correct file — no copy-paste.
Frequently asked questions
- Is io.github.cyanheads/nhtsa-vehicle-safety-mcp-server safe to use?
- io.github.cyanheads/nhtsa-vehicle-safety-mcp-server scores 79/100 — grade B, which is a solid posture with a few gaps worth reading. It passes 5 of the 9 OWASP MCP Top-10 checks that apply to it, with Insufficient Input Validation, Missing Authentication, Inadequate Rate Limiting, and Supply Chain Risk returning a warning rather than a pass. 1 further check does not apply to this server's transport and is excluded from the score entirely — skipped is not the same as failed. This is what the scanner found on 2026-08-05, not a guarantee. Re-run it yourself with `npx mcpr scan`.
- What is the io.github.cyanheads/nhtsa-vehicle-safety-mcp-server trust score based on?
- Ten checks derived from the OWASP MCP Top 10, run against the live server by the open-source MCP Vouch scanner. Applicable checks are summed and scaled to 0–100; checks that do not apply to the server's transport are skipped and leave the denominator entirely.
- How do I install io.github.cyanheads/nhtsa-vehicle-safety-mcp-server?
- io.github.cyanheads/nhtsa-vehicle-safety-mcp-server is installed like any other MCP server — add it to your client's MCP configuration. Cross-client one-click install is coming to MCP Registry; until then, the repository and homepage links on this page carry the maintainer's own instructions.