ICUICU
critical

ai.smithery/mjucius-cozi_mcp

v1.14.0

Manage your family's calendars and lists in Cozi. View, create, and update appointments; organize…

MCP RegistrysmitheryFirst seen Feb 24, 2026Source

5

Total

4

Critical

0

High

1

Medium

Findings

unknown
criticalDE-002Data ExfiltrationHigh ConfidenceLine 0

Environment file access

Detected by automated pattern matching (rule DE-002) with medium confidence. May be a false positive.

    61: *.key
    62: .env.local
>>> 63: .env.production
    64: secrets.json
    65: credentials.json
Report false positive
criticalDE-002Data ExfiltrationHigh ConfidenceLine 0

Environment file access

Detected by automated pattern matching (rule DE-002) with medium confidence. May be a false positive.

    60: *.pem
    61: *.key
>>> 62: .env.local
    63: .env.production
    64: secrets.json
Report false positive
criticalDE-002Data ExfiltrationHigh ConfidenceLine 0

Environment file access

Detected by automated pattern matching (rule DE-002) with medium confidence. May be a false positive.

    1: # Cozi MCP Server Environment Variables
>>> 2: # Copy this file to .env and fill in your actual Cozi credentials
    3: 
    4: # Your Cozi account username/email
Report false positive
criticalDE-002Data ExfiltrationHigh ConfidenceLine 0

Environment file access

Detected by automated pattern matching (rule DE-002) with medium confidence. May be a false positive.

    33: 
    34: # Virtual environments
>>> 35: .env
    36: .venv
    37: env/
Report false positive
mediumEN-001unknownMedium ConfidenceLine 0

High-entropy string (4.5 bits/char) — possible encoded payload

Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.

Report false positive

Scan History

DateRiskFindings
Feb 26, 2026critical5
Feb 24, 2026critical5