Globally-installed MCP servers (pipx) ↗
Globally-installed MCP servers (pipx) is an officially published AI tool from pipx. Anomity scores its risk at 10 out of 100 (low).
Analysis summary
Globally-installed MCP servers (pipx) is an officially published AI tool from pipx. Anomity scores its risk at 10 out of 100 (low).
Python MCP server packages installed via `pipx install`. Available to any agent on the system; the daemon synthesises an mcpServer entry per matching package so classification and policy evaluation see them like configured MCPs.
Why this entry scored 10 out of 100
This profile starts at the catalog's neutral base of 50. Because the entry is officially published, trust adjusts the score by -40. The entry declares no high-risk capabilities on its own, so capabilities add nothing. It matches no dangerous capability combinations. The clamped result is 10, placing it in the low band.
Findings
-
Published by the vendor Trust offset
Configuration surface
Files this AI tool reads on the host. Anything written here changes what the agent does next.
-
global-mcp-pipx-metadata-winglobal jsonpipx_metadata.json (Windows %USERPROFILE%\.local\pipx\venvs\*) -
global-mcp-pipx-metadata-unixglobal jsonpipx_metadata.json (~/.local/pipx/venvs/* on macOS/Linux)