Summary
One of the tools in server-everything (get-env) returns the entire process environment of the server to the client. In an agent host that means any API key, token or credential present in the server's environment is one tool call away from the model — no prompt injection required, just a tool call the model is entitled to make.
Environment
@modelcontextprotocol/server-everything 2.0.0 (npm latest), server info reported as mcp-servers/everything
- MCP protocol version reported by the server:
2025-06-18
- Host OS: Windows x64, harness run locally over stdio
- 13 tools exposed by the server
Reproduction
-
Start the server with a canary credential in its environment, e.g.
MCPBENCH_CANARY=1 SK_MCPBENCH_CANARY=1 npx -y @modelcontextprotocol/server-everything
(any env var name/value works; these are just sentinels)
-
Call the get-env tool with no arguments.
-
Observed: the response contains the canary values verbatim, together with everything else in the process environment.
Observed result
The probe recorded the tool get-env returning, among many unrelated entries (paths, locale, toolchain variables), the two injected sentinel secrets:
response leaked ['mcpbench-canary-3f9a1c2d7e5b', 'sk-mcpbench-canary-...']
The full raw response is committed as evidence in the benchmark below. Nothing was exfiltrated anywhere: this was a locally started server with sentinel values created for the test.
Why it matters more than it looks
server-everything is the reference/demo server people read and copy when they build their own MCP server. A tool that dumps the environment teaches the wrong pattern.
- Agent hosts run MCP servers as child processes with the host's environment. A dump of that environment commonly includes provider API keys, database URLs and cloud credentials.
- The capability is not gated, not flagged as dangerous, and its name (
get-env) does not suggest credential exposure.
Suggested fixes (any of these)
- Remove the tool, or gate it behind an explicit opt-in flag/env var that defaults to off.
- If it is kept for debugging, return key names only (no values), or redact values whose key matches secret-ish patterns (
*_KEY, *_TOKEN, *_SECRET, PASSWORD*, AWS_*, …).
- Add a short warning in the README next to the tool list, so the pattern is not copied into new servers.
Evidence / methodology
- Harness, case corpus and scorecard: https://github.com/CieveMe/mcp-security-benchmark
(target config: targets/everything-public.json, finding: results/everything-public/scorecard.md, case id cred-env-canary-dump / category credential-exposure)
- The harness is deliberately small: 14 cases, and 100/100 means "no findings in this corpus", not "secure". It covers a few well-known failure shapes and does not cover authentication, transport, sandboxing or dependency risk.
- Single machine, single run, sentinel credentials only; no third-party instance was touched.
Happy to re-run against a specific tag/commit if that helps narrow it down.
Summary
One of the tools in
server-everything(get-env) returns the entire process environment of the server to the client. In an agent host that means any API key, token or credential present in the server's environment is one tool call away from the model — no prompt injection required, just a tool call the model is entitled to make.Environment
@modelcontextprotocol/server-everything2.0.0 (npmlatest), server info reported asmcp-servers/everything2025-06-18Reproduction
Start the server with a canary credential in its environment, e.g.
(any env var name/value works; these are just sentinels)
Call the
get-envtool with no arguments.Observed: the response contains the canary values verbatim, together with everything else in the process environment.
Observed result
The probe recorded the tool
get-envreturning, among many unrelated entries (paths, locale, toolchain variables), the two injected sentinel secrets:The full raw response is committed as evidence in the benchmark below. Nothing was exfiltrated anywhere: this was a locally started server with sentinel values created for the test.
Why it matters more than it looks
server-everythingis the reference/demo server people read and copy when they build their own MCP server. A tool that dumps the environment teaches the wrong pattern.get-env) does not suggest credential exposure.Suggested fixes (any of these)
*_KEY,*_TOKEN,*_SECRET,PASSWORD*,AWS_*, …).Evidence / methodology
(target config:
targets/everything-public.json, finding:results/everything-public/scorecard.md, case idcred-env-canary-dump/ categorycredential-exposure)Happy to re-run against a specific tag/commit if that helps narrow it down.