A wave of newly published Model Context Protocol (MCP) packages on PyPI expanded AI-agent access to browsers, Slack, Elasticsearch, MATLAB, UniFi Access, Lean, and Blender, while several projects openly documented significant security risks. Packages such as selenium-mcp, browsegrab, workos-slack-mcp-server, matlab-mcp-python, unifi-access-mcp, and lean-lsp-mcp advertised structured tool access for browser control, workspace messaging, code execution, infrastructure management, and theorem-prover interaction. Some maintainers included safeguards such as read-only modes, confirmation prompts, blocked-function lists, filename sanitization, and bearer-token authentication, but multiple listings also warned that MCP servers can expose local filesystems, execute privileged actions, or run arbitrary code if deployed without isolation.

Trace attribution and downstream blast radius.
13 events from the most recent confirmed update back to the earliest known activity.
The UniFi Access MCP Server version 0.1.4 was published on PyPI, exposing UniFi Access management functions to LLMs and automation platforms. The package described safe-by-default permissions and preview-before-confirm safeguards for mutating actions.
PyPI documentation for elasticsearch-client-mcp-py included an example configuration for an Alibaba Cloud Elasticsearch endpoint with a plaintext username and password. This appeared in package references for versions 0.5.1 and 0.6.0, creating a public credential exposure concern.
The elasticsearch-client-mcp-py package was published on PyPI as version 0.5.0, providing an Elasticsearch MCP server with read-only mode, search-size limits, and confirmation for write operations. The package metadata indicated it was uploaded using uv and not via Trusted Publishing.
A package named elasticsearch-client-mcp-py version 0.3.0 was published on PyPI. The reference provides no additional synopsis or incident details beyond the publication.
BlenderMCP version 1.5.5 was published on PyPI, connecting Blender to Claude AI through MCP for 3D scene manipulation. The documentation explicitly warned that its execute_blender_code capability can run arbitrary Python code inside Blender and is potentially dangerous.
MATLAB MCP Server version 1.3.0 was published on PyPI, enabling AI agents to execute MATLAB code through MCP. The package documentation highlighted security controls including blocked-function lists, filename sanitization, and session isolation.
A package named elasticsearch-client-mcp-py version 0.1.2 was published on PyPI. The reference provides no synopsis beyond the package publication.
browsegrab version 0.1.0 was published on PyPI as a lightweight browser automation library for local LLMs with an MCP-native server. The package emphasized token-efficient browser interaction using Playwright, accessibility-tree snapshots, and markdown conversion.
The workos-slack-mcp-server package was published on PyPI as version 1.0.0, providing a production-ready Slack MCP server for AI agents. The reference describes supported Slack operations and integration setup, but no security incident or breach.
The New Stack published a report describing Google's early WebMCP implementation in Chrome and the author's testing with a mock flight-search demo, WebMCP inspector, and Gemini API key. The article said the feature was experimental, required a Chrome preview build and feature flag, and was not enabled on ordinary websites by default.
Selenium MCP version 1.3.0 was published on PyPI, exposing Selenium WebDriver browser automation capabilities to AI agents through MCP tools. The package documentation included operational guidance and a recommended system prompt for safer automation.
The lean-lsp-mcp package was published on PyPI as version 0.25.1, offering an MCP server for agentic interaction with the Lean theorem prover. Its documentation warned that MCP introduces security concerns such as local filesystem access and lack of input/output validation.
A package named td-mcp version 0.1.1 was published on PyPI. The reference provides no additional synopsis or incident details beyond the publication.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
14 references tracked. Mallory keeps watching after this page renders.
pypi.org
Open sourcepypi.org
Open sourcepypi.org
Open sourcepypi.org
Open sourcethenewstack.io
Open sourcepypi.org
Open sourcepypi.org
Open sourcepypi.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.