Bitwarden MCP — security audit
Bitwarden MCP: trust score 50/100 — 1 capability surface.
Trust score
50
Grade D
Risk flags
Community-authored
Maintained by Community. Confirm the repo and signing before installing.
No public repository linked
Without a public repo we cannot independently audit the code. Caution warranted.
Capability surface
Secrets handling
Medium riskRequires API keys, tokens or credentials in env vars. Watch for placeholder leaks.
Evidence:
password
Trust signals
Total trust score is the sum of these contributions. Each signal carries a fixed weight.
Verified by Loadout
+20 / 20
Manually verified.
Official author
+0 / 15
Maintained by community contributors.
Community traction
+15 / 20
1,100 GitHub stars.
Public source
+0 / 15
No linked public repository.
Stability
+0 / 15
Stability not yet assessed.
Capability surface
+15 / 15
No high-risk capabilities detected.
Disclaimer
This is an automated heuristic triage. It does not replace a hand-rolled code audit. Use it to prioritise which servers deserve a deeper look — especially anything carrying high-risk capabilities like shell execution or filesystem write.