com.glean/mcp
v1.0.1Remote MCP Server that securely connects Glean Enterprise Knowledge with your IDE, LLM, or agents.
54
Total
0
Critical
24
High
30
Medium
Findings
unknownDecoded base64 content: r���W�� +��ޚ�^
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: r���W�� +��ޚ�^
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: r���W�� +��ޚ�^
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: r���W�� +��ޚ�^
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: ��^��'��m��-��%
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: ��^��'��m��-��%
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: ��^��'��m��-��%
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: r���W�� +��ޚ�^
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: r���W�� +��ޚ�^
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: r���W�� +��ޚ�^
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: r���W�� +��ޚ�^
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: ��^��'��m��-��%
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: ��^��'��m��-��%
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: r��zڮ��?�^��Oz
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: r��zڮ��?�^��Oz
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: ��^��'��m��-��%
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: r��zڮ��?�^��Oz
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: r���W�� +��ޚ�^
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: r���W�� +��ޚ�^
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: r���W�� +��ޚ�^
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: ��^��'��m��-��%
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: ��^��'��m��-��%
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: �+a��ۖ���������ަ�"���
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: <svg viewBox="0 0 32 32" fill="none" xmlns="http://www.w3.org/2000/svg"> <path d="M24.3006 2.95427L2
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (4.9 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (4.8 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (4.9 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (5.1 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (4.8 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (4.9 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positivePossible Base64-encoded payload (long encoded string)
Detected by automated pattern matching (rule OB-001) with medium confidence. May be a false positive.
28: **Future improvement:** When the MCP registry supports URL template variables (schema 2025-12-11+), we will update to use `https://{instance}-be.glean.com/mcp/{server-name}` which will prompt users for their instance name during setup. The template version is saved in `server-2025-12-11.json` for when the mcp-publisher tool is updated to support the newer schema.
29:
>>> 30: See the [generic server.json documentation](https://github.com/modelcontextprotocol/registry/blob/main/docs/reference/server-json/generic-server-json.md) for more details.
31:
32: ## Publishing ProcessReport false positivePossible Base64-encoded payload (long encoded string)
Detected by automated pattern matching (rule OB-001) with medium confidence. May be a false positive.
67: if: steps.check.outputs.should_publish == 'true'
68: run: |
>>> 69: curl -L "https://github.com/modelcontextprotocol/registry/releases/latest/download/mcp-publisher_$(uname -s | tr '[:upper:]' '[:lower:]')_$(uname -m | sed 's/x86_64/amd64/;s/aarch64/arm64/').tar.gz" | tar xz mcp-publisher
70:
71: - name: Login to MCP RegistryReport false positiveHigh-entropy string (4.6 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (5.0 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (4.5 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (4.9 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (4.6 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positivePossible Base64-encoded payload (long encoded string)
Detected by automated pattern matching (rule OB-001) with medium confidence. May be a false positive.
5: ### Features
6:
>>> 7: * Support custom domains in MCP server URL template ([#6](https://github.com/gleanwork/remote-mcp-server/issues/6)) ([1119370](https://github.com/gleanwork/remote-mcp-server/commit/1119370be057aa0671d906dee5604900808ea9ab))
8:
9: ## 1.1.0 (2026-01-19)Report false positivePossible Base64-encoded payload (long encoded string)
Detected by automated pattern matching (rule OB-001) with medium confidence. May be a false positive.
11: ### Features
12:
>>> 13: * Add release-it and improve publish workflow ([#3](https://github.com/gleanwork/remote-mcp-server/issues/3)) ([6ba5a68](https://github.com/gleanwork/remote-mcp-server/commit/6ba5a68e0e8efac10dc1e0755f9c3476e1ca86e2))
14: * Add remotes configuration for MCP registry one-click install ([ac9ebcd](https://github.com/gleanwork/remote-mcp-server/commit/ac9ebcd5bd3126403bac83fa17bf64cbdca2c363))
15: * Add remotes configuration for one-click MCP installer ([be8ecd5](https://github.com/gleanwork/remote-mcp-server/commit/be8ecd5a452f3471d34242af43dd230cc01d09fc))Report false positivePossible Base64-encoded payload (long encoded string)
Detected by automated pattern matching (rule OB-001) with medium confidence. May be a false positive.
12:
13: * Add release-it and improve publish workflow ([#3](https://github.com/gleanwork/remote-mcp-server/issues/3)) ([6ba5a68](https://github.com/gleanwork/remote-mcp-server/commit/6ba5a68e0e8efac10dc1e0755f9c3476e1ca86e2))
>>> 14: * Add remotes configuration for MCP registry one-click install ([ac9ebcd](https://github.com/gleanwork/remote-mcp-server/commit/ac9ebcd5bd3126403bac83fa17bf64cbdca2c363))
15: * Add remotes configuration for one-click MCP installer ([be8ecd5](https://github.com/gleanwork/remote-mcp-server/commit/be8ecd5a452f3471d34242af43dd230cc01d09fc))
16: * Upgrade server.json to 2025-12-11 schema with URL variables ([#4](https://github.com/gleanwork/remote-mcp-server/issues/4)) ([e2c73f6](https://github.com/gleanwork/remote-mcp-server/commit/e2c73f6c37cbfc81a56aeacd26a3e5b658dc2914))Report false positivePossible Base64-encoded payload (long encoded string)
Detected by automated pattern matching (rule OB-001) with medium confidence. May be a false positive.
13: <p align="center">
14: <a href="https://registry.modelcontextprotocol.io"><img src="https://badge.mcpx.dev?type=server" alt="MCP Server"></a>
>>> 15: <a href="https://github.com/gleanwork/.github/blob/main/docs/repository-stability.md#ga"><img src="https://img.shields.io/badge/-GA-F6F3EB?style=flat-square&logo=data:image/svg+xml;base64,PHN2ZyB2aWV3Qm94PSIwIDAgMzIgMzIiIGZpbGw9Im5vbmUiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyI+CjxwYXRoIGQ9Ik0yNC4zMDA2IDIuOTU0MjdMMjAuNzY1NiAwLjE5OTk1MUwxNy45MDI4IDMuOTk1MjdDMTMuNTY1MyAxLjkzNDk1IDguMjMwMTkgMy4wODQzOSA1LjE5Mzk0IDcuMDA5ODNDMS42NTg4OCAxMS41NjQyIDIuNDgzIDE4LjExMzggNy4wMzczOCAyMS42NDg5QzguNzcyMzggMjIuOTkzNSAxMC43ODkzIDIzLjcwOTIgMTIuODI3OSAyMy44MTc3QzE2LjE0NjEgMjQuMDEyOCAxOS41MDc3IDIyLjYyNDggMjEuNjc2NSAxOS44MDU1QzI0LjczNDQgMTUuODggMjQuNTE3NSAxMC40MTQ4IDIxLjQ1OTYgNi43Mjc4OUwyNC4zMDA2IDIuOTU0MjdaTTE4LjExOTcgMTcuMDUxMkMxNi4xMDI4IDE5LjYzMiAxMi4zNzI1IDIwLjEwOTEgOS43NzAwMSAxOC4wOTIyQzcuMTg5MTkgMTYuMDc1MiA2LjcxMjA3IDEyLjMyMzMgOC43MjkwMSA5Ljc0MjQ2QzkuNzA0OTQgOC40ODQ1OCAxMS4xMTQ2IDcuNjgyMTQgMTIuNjc2MSA3LjQ4Njk2QzEzLjA0NDggNy40NDM1OCAxMy40MTM1IDcuNDIxOSAxMy43ODIyIDcuNDQzNThDMTQuOTc1IDcuNTA4NjUgMTYuMTI0NCA3Ljk0MjM5IDE3LjA3ODcgOC42Nzk3N0MxOS42NTk1IDEwLjcxODQgMjAuMTM2NiAxNC40NzAzIDE4LjExOTcgMTcuMDUxMloiIGZpbGw9IndoaXRlIi8+CjxwYXRoIGQ9Ik0yNC41MTc2IDIxLjY5MjJDMjMuOTMyIDIyLjQ1MTMgMjMuMjgxNCAyMy4xMjM2IDIyLjU2NTcgMjMuNzUyNUMyMS44NzE3IDI0LjMzODEgMjEuMTEyNyAyNC44ODAzIDIwLjMxMDIgMjUuMzM1N0MxOS41Mjk1IDI1Ljc2OTUgMTguNjgzNyAyNi4xMzgyIDE3LjgzNzggMjYuNDIwMUMxNi45OTIgMjYuNzAyIDE2LjEwMjggMjYuODk3MiAxNS4yMTM3IDI3LjAwNTdDMTQuMzI0NSAyNy4xMTQxIDEzLjQzNTMgMjcuMTU3NSAxMi41MjQ0IDI3LjA5MjRDMTEuNjEzNSAyNy4wMjczIDEwLjcyNDMgMjYuODc1NSA5Ljg1Njg0IDI2LjY1ODdMOS42NjE2NSAyNy4zNzQzTDguNzcyNDYgMzAuOTk2MkM5LjkwMDIxIDMxLjI5OTggMTEuMDQ5NyAzMS40NzMzIDEyLjIyMDggMzEuNTZDMTIuMjY0MiAzMS41NiAxMi4zMjkyIDMxLjU2IDEyLjM3MjYgMzEuNTZDMTMuNTAwMyAzMS42MjUxIDE0LjY0OTggMzEuNTgxNyAxNS43NTU4IDMxLjQ1MTZDMTYuOTI3IDMxLjI5OTggMTguMDk4MSAzMS4wMzk1IDE5LjIyNTggMzAuNjcwOEMyMC4zNTM2IDMwLjMwMjIgMjEuNDU5NyAyOS44MjUgMjIuNTAwNyAyOS4yMzk1QzIzLjU2MzQgMjguNjUzOSAyNC41NjEgMjcuOTM4MiAyNS40OTM1IDI3LjE1NzVDMjYuNDQ3OCAyNi4zNTUgMjcuMzE1MyAyNS40NDQyIDI4LjA3NDQgMjQuNDQ2NUMyOC4xODI4IDI0LjMxNjQgMjguMjY5NSAyNC4xNjQ2IDI4LjM3OCAyNC4wMTI4TDI0Ljc3NzkgMjEuMzQ1MkMyNC42Njk0IDIxLjQ1MzcgMjQuNjA0NCAyMS41ODM4IDI0LjUxNzYgMjEuNjkyMloiIGZpbGw9IndoaXRlIi8+Cjwvc3ZnPg==&labelColor=343CED" alt="GA"></a>
16: </p>
17: Report false positivePossible Base64-encoded payload (long encoded string)
Detected by automated pattern matching (rule OB-001) with medium confidence. May be a false positive.
13: * Add release-it and improve publish workflow ([#3](https://github.com/gleanwork/remote-mcp-server/issues/3)) ([6ba5a68](https://github.com/gleanwork/remote-mcp-server/commit/6ba5a68e0e8efac10dc1e0755f9c3476e1ca86e2))
14: * Add remotes configuration for MCP registry one-click install ([ac9ebcd](https://github.com/gleanwork/remote-mcp-server/commit/ac9ebcd5bd3126403bac83fa17bf64cbdca2c363))
>>> 15: * Add remotes configuration for one-click MCP installer ([be8ecd5](https://github.com/gleanwork/remote-mcp-server/commit/be8ecd5a452f3471d34242af43dd230cc01d09fc))
16: * Upgrade server.json to 2025-12-11 schema with URL variables ([#4](https://github.com/gleanwork/remote-mcp-server/issues/4)) ([e2c73f6](https://github.com/gleanwork/remote-mcp-server/commit/e2c73f6c37cbfc81a56aeacd26a3e5b658dc2914))
17: Report false positivePossible Base64-encoded payload (long encoded string)
Detected by automated pattern matching (rule OB-001) with medium confidence. May be a false positive.
14: * Add remotes configuration for MCP registry one-click install ([ac9ebcd](https://github.com/gleanwork/remote-mcp-server/commit/ac9ebcd5bd3126403bac83fa17bf64cbdca2c363))
15: * Add remotes configuration for one-click MCP installer ([be8ecd5](https://github.com/gleanwork/remote-mcp-server/commit/be8ecd5a452f3471d34242af43dd230cc01d09fc))
>>> 16: * Upgrade server.json to 2025-12-11 schema with URL variables ([#4](https://github.com/gleanwork/remote-mcp-server/issues/4)) ([e2c73f6](https://github.com/gleanwork/remote-mcp-server/commit/e2c73f6c37cbfc81a56aeacd26a3e5b658dc2914))
17:
18: ### Bug FixesReport false positivePossible Base64-encoded payload (long encoded string)
Detected by automated pattern matching (rule OB-001) with medium confidence. May be a false positive.
18: ### Bug Fixes
19:
>>> 20: * Update release-it config to disable npm and fix bumper plugin ([#5](https://github.com/gleanwork/remote-mcp-server/issues/5)) ([c15e534](https://github.com/gleanwork/remote-mcp-server/commit/c15e53492f6fbac7a292d3a79b5999adb47e0441))Report false positiveHigh-entropy string (4.5 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (4.5 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (4.6 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (4.6 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (4.6 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (4.6 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positivePossible Base64-encoded payload (long encoded string)
Detected by automated pattern matching (rule OB-001) with medium confidence. May be a false positive.
43: **Binary download:**
44: ```bash
>>> 45: curl -L "https://github.com/modelcontextprotocol/registry/releases/latest/download/mcp-publisher_$(uname -s | tr '[:upper:]' '[:lower:]')_$(uname -m | sed 's/x86_64/amd64/;s/aarch64/arm64/').tar.gz" | tar xz mcp-publisher
46: ```
47: Report false positivePossible Base64-encoded payload (long encoded string)
Detected by automated pattern matching (rule OB-001) with medium confidence. May be a false positive.
93: ### Common Errors
94:
>>> 95: **"deprecated schema detected"**: The mcp-publisher version doesn't support the schema version in server.json. Update to the latest mcp-publisher or use an older schema version. Check the [schema changelog](https://github.com/modelcontextprotocol/registry/blob/main/docs/reference/server-json/CHANGELOG.md) for supported versions.
96:
97: **"invalid remote URL"**: The URL in `remotes` contains unsupported characters or invalid format. Ensure the URL is a valid HTTPS endpoint.Report false positivePossible Base64-encoded payload (long encoded string)
Detected by automated pattern matching (rule OB-001) with medium confidence. May be a false positive.
163: - [MCP Registry Documentation](https://github.com/modelcontextprotocol/registry)
164: - [server.json Schema](https://static.modelcontextprotocol.io/schemas/2025-10-17/server.schema.json)
>>> 165: - [Generic server.json Format](https://github.com/modelcontextprotocol/registry/blob/main/docs/reference/server-json/generic-server-json.md)
166: - [Official Registry Requirements](https://github.com/modelcontextprotocol/registry/blob/main/docs/reference/server-json/official-registry-requirements.md)
167: - [Anthropic MCP Directory Policy](https://support.claude.com/en/articles/11697096-anthropic-mcp-directory-policy)Report false positivePossible Base64-encoded payload (long encoded string)
Detected by automated pattern matching (rule OB-001) with medium confidence. May be a false positive.
164: - [server.json Schema](https://static.modelcontextprotocol.io/schemas/2025-10-17/server.schema.json)
165: - [Generic server.json Format](https://github.com/modelcontextprotocol/registry/blob/main/docs/reference/server-json/generic-server-json.md)
>>> 166: - [Official Registry Requirements](https://github.com/modelcontextprotocol/registry/blob/main/docs/reference/server-json/official-registry-requirements.md)
167: - [Anthropic MCP Directory Policy](https://support.claude.com/en/articles/11697096-anthropic-mcp-directory-policy)
168: - [Glean MCP Server Documentation](https://docs.glean.com/administration/platform/mcp/about)Report false positive