Skip to main content

Is smithery.ai a Scam? Security Check Results - smithery.ai Reviews

smithery.ai favicon

Is smithery.ai Safe? Security Analysis for Smithery - Model Context Protocol Registry

Check if smithery.ai is a scam or legitimate. Free security scan and reviews.

TechnologyIcelandsmall
Next.jsReactCloudflare DNSSupabase (storage for server icons)JavaScript+1 more
Analyzed 8/3/2025Completed 1:17:07 AM
67
Security Score
MEDIUM RISK

AI Summary

Smithery.ai is a technology platform specializing in the Model Context Protocol (MCP) registry, enabling AI agents to extend their capabilities by integrating with thousands of community-built skills and extensions. The platform targets developers and AI practitioners seeking to enhance AI agent functionality through a rich ecosystem of MCP servers. The website showcases a variety of MCP servers categorized by functionality such as browser automation, memory management, code collaboration, and web search, providing detailed descriptions and usage guidance. Technically, the website is built using modern web technologies including Next.js and React, hosted with Cloudflare DNS and leveraging Supabase for storage of server icons. The site demonstrates good performance and mobile optimization, with a clean and professional design that facilitates user navigation and discovery of MCP servers. Analytics are implemented via a third-party service (dubcdn.com), indicating minimal user tracking. From a security perspective, the site employs HTTPS and domain transfer protection but lacks DNSSEC and published security policies or incident response information. No critical vulnerabilities or exposed sensitive data were detected. Privacy compliance is limited as no privacy or cookie policies are present, which is a notable gap for GDPR and related regulations. Overall, Smithery.ai presents a credible and specialized platform for AI agent extension, with solid technical infrastructure but room for improvement in privacy and security transparency. Strategic enhancements in policy publication and security headers would strengthen trust and compliance.

Detected Technologies

Next.jsReactCloudflare DNSSupabase (storage for server icons)JavaScriptTypeScript (implied by MCP server descriptions)

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

Smithery.ai operates in the niche technology sector focused on AI agent integration and extension via the Model Context Protocol. The platform's business model centers on providing a registry and deployment environment for MCP servers, facilitating community contributions and developer adoption. Its market position is that of an emerging startup (founded in 2024) targeting AI developers and organizations building intelligent agents. The platform's competitive advantage lies in its extensive catalog of MCP servers and integration capabilities with popular AI tools like Claude and Cursor. Revenue streams likely include hosting, deployment services, and possibly premium MCP features. The absence of direct contact information and formal policies suggests an early-stage operation with potential growth in governance and compliance. Partnerships with cloud providers and analytics services support its ecosystem. The platform's growth indicators include a large number of MCP servers and active community engagement.

Extracted Contact Information

Marketing Intelligence Data

Email Addresses (1)

h*****@ref.tools

Security Posture Analysis

Comprehensive Security Assessment

Smithery.ai demonstrates a moderate security maturity level with HTTPS enforced and domain transfer protection enabled. However, the lack of DNSSEC and absence of published security policies or incident response contacts indicate gaps in security governance. No vulnerabilities or exposed sensitive data were identified in the analyzed content. The site does not implement advanced security headers, which could improve protection against common web attacks. Privacy compliance is weak due to missing privacy and cookie policies, which may expose the platform to regulatory risks under GDPR and similar frameworks. Incident response readiness is unclear, with no dedicated security contact channels found. Overall, the security posture is adequate for a startup but requires enhancements in policy transparency, DNS security, and security header implementation to meet best practices and regulatory expectations.

Strategic Recommendations

Priority Actions for Security Improvement

1

Enable DNSSEC to enhance DNS security and prevent spoofing.

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Description:

Extend your agent's capabilities with Model Context Protocol servers. Integrate your AI with 5671 skills and extensions built by the community.

Key Services:
Model Context Protocol (MCP) server registryAI agent skill and extension integrationHosting and deployment of MCP serversDocumentation and playground for MCP usage
Content Quality:

good

Branding:

consistent

Technical Stack

Technologies:
Next.jsReactCloudflare DNSSupabase (storage for server icons)JavaScriptTypeScript (implied by MCP server descriptions)
Frameworks:
Next.js
Platforms:
CloudflareSupabase
Performance:

fast

Mobile:

good

Accessibility:

basic

SEO:

basic

Security Assessment

Security Score:
75/100
Best Practices:
  • HTTPS enabled
  • Domain status clientTransferProhibited to prevent unauthorized transfers
  • Use of privacy protection for WHOIS

Analytics & Tracking

Services:
dubcdn.com analytics
Tracking Level:minimal
Privacy Compliance:poor

Advertising & Marketing

Tracking Pixels:
dubcdn.com analytics
Marketing Tools:
dubcdn.com analytics
Transparency Level:basic

Website Quality Assessment

Design Quality:good
User Experience:good
Content Relevance:good
Navigation Clarity:good
Professionalism:good
Trustworthiness:moderate

Key Observations

1

Website is a technology platform for AI agent integration via Model Context Protocol servers.

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

30/100
Score

Missing X-Frame-Options header

HIGH

Prevents clickjacking attacks

Missing X-Content-Type-Options header

MEDIUM

Prevents MIME type sniffing

Missing Content-Security-Policy header

HIGH

Controls resources the browser is allowed to load

Missing X-XSS-Protection header

MEDIUM

Legacy XSS protection (deprecated but still recommended)

Missing Referrer-Policy header

LOW

Controls referrer information sent with requests

Missing Permissions-Policy header

MEDIUM

Controls browser features and APIs

Sensitive data may be cached

LOW

Cache-Control header should include "no-store" for sensitive pages

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

53/100
Score

No Cookie Policy found

HIGH

GDPR requires clear information about cookie usage

No Cookie Consent Banner found

HIGH

GDPR requires explicit consent for non-essential cookies

No Data Protection Officer mentioned

LOW

Large organizations may need to designate a DPO under GDPR

Privacy policy may not be GDPR compliant

MEDIUM

Privacy policy lacks explicit GDPR compliance elements

GDPR Compliance Analysis

Privacy Policy85% confidence
Cookie Policy0% confidence
Contact Information Found90% confidence
emailphone

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

73/100
Score

No incident response procedures found

HIGH

NIS2 requires documented incident response and business continuity plans

No security contact information

HIGH

NIS2 requires clear incident reporting channels

No NIS2 reference found

LOW

Consider explicitly mentioning NIS2 compliance efforts

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

55/100
Score

DMARC not enforcing

MEDIUM

DMARC policy is set to "none"

No DMARC reporting

LOW

DMARC aggregate reports not configured

No DKIM record found

MEDIUM

DKIM adds cryptographic signatures to emails

No BIMI Record

LOW

BIMI displays brand logos in email clients

No MTA-STS Policy

MEDIUM

MTA-STS enforces TLS for email delivery

No TLS-RPT Record

LOW

TLS-RPT provides reporting for email TLS issues

SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security
SPF Details
Record:
v=spf1 include:spf.messagingengine.com include:_spf.google.com ~all
DNS Lookups:2/10
Policy:~all
DMARC Details
Policy:none

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

72/100
Score

Weak Protocols Supported

HIGH

Server supports weak protocols: TLSv1.1

OCSP Stapling Not Enabled

LOW

OCSP stapling improves performance and privacy

Certificate Transparency Not Implemented

LOW

Certificate is not logged in Certificate Transparency logs

SSL Certificate Expires Within 90 Days

MEDIUM

SSL certificate expires in 47 days

Partial SSL/TLS Assessment

LOW

Completed 3 of 4 security checks due to time constraints

Protocol Support

TLSv1.3TLSv1.2TLSv1.1

OCSP Status

OCSP Stapling Disabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

75/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

CAA Records Not Configured

LOW

Certificate Authority Authorization (CAA) records not found

Domain Delete Lock Not Enabled

LOW

Domain can be deleted without additional verification

DMARC Policy Set to None

LOW

DMARC is configured but not enforcing any policy

Domain Registration Details

Domain Age
0 years(young)
Expiry Risk
none(477 days)
Protection Level
basicDNSSEC OFF
Suspicious Indicators Detected
  • Privacy/proxy registration detected

DNS Records

A Records:76.76.21.21
Name Servers:
iris.ns.cloudflare.com
walt.ns.cloudflare.com
MX Records:
10: alt4.aspmx.l.google.com
5: alt2.aspmx.l.google.com
1: aspmx.l.google.com
10: alt3.aspmx.l.google.com
5: alt1.aspmx.l.google.com
SOA:Serial: 2376126370, TTL: 1800s

DNSSEC Status

DNSSEC Not Enabled

DNS Performance

Resolution Time:76ms

SPF Analysis

SPF Record:
v=spf1 include:spf.messagingengine.com include:_spf.google.com ~all

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

100/100
Score

Good Network Security Posture

LOW

No unnecessary services detected on common risky ports

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

The website is built on a modern technology stack featuring Next.js and React, ensuring a performant and responsive user experience. Hosting is managed via Cloudflare DNS and CDN services, with Supabase used for storage of media assets. The site loads quickly and is optimized for mobile devices, though accessibility features appear basic. SEO optimization is present but could be improved with richer metadata and structured data. The use of third-party analytics is minimal and does not appear intrusive. Technical debt is low given the recent domain registration and modern framework usage. Opportunities exist to enhance security configurations and privacy compliance to reduce technical risks and improve user trust.
Analyze Another Website