Oxvault Oxvault

Validation Sweep Results

33 MCP servers + 79 HuggingFace models scanned with Oxvault Scanner v0.4.1 on 2026-05-11. Full transparency — every finding is public.

112
Total
33
MCP
79
HF Models
3
Critical
8
High
1808
Warning
93%
Precision
12/12
CVE Rate
Artifact Findings
wonderwhy-er/DesktopCommanderMCP 24
mcpotato/42-eicar-street 6
github/github-mcp-server 31
HuggingFaceTB/SmolLM-360M 464
HuggingFaceTB/SmolLM-135M 436
BAAI/bge-base-en-v1.5 9
BAAI/bge-small-en-v1.5 9
microsoft/DialoGPT-small 4
facebook/m2m100_418M 4
microsoft/speecht5_tts 4
gitingest-app/gitingest-mcp 1
sentence-transformers/all-mpnet-base-v2 133
sentence-transformers/all-MiniLM-L12-v2 130
sentence-transformers/all-distilroberta-v1 94
cross-encoder/ms-marco-MiniLM-L-6-v2 88
sentence-transformers/multi-qa-MiniLM-L6-cos-v1 76
sentence-transformers/all-MiniLM-L6-v2 76
sentence-transformers/paraphrase-MiniLM-L6-v2 76
intfloat/e5-base-v2 60
intfloat/e5-small-v2 48
thenlper/gte-small 48
google-t5/t5-small 21
bigscience/bloom-560m 13
openai-community/gpt2 11
sentence-transformers/sentence-t5-base 12
hf-internal-testing/tiny-random-bert 9
dslim/bert-base-NER 7
google-bert/bert-base-uncased 6
openai/clip-vit-large-patch14 6
microsoft/mpnet-base 4
Helsinki-NLP/opus-mt-fr-en 4
hf-internal-testing/tiny-random-distilbert 5
hf-internal-testing/tiny-random-gpt2 6
FacebookAI/xlm-roberta-base 6
Qwen/Qwen2.5-0.5B 3
albert/albert-base-v2 4
facebook/bart-base 6
openai/clip-vit-base-patch32 4
microsoft/codebert-base 2
distilbert/distilbert-base-uncased 4
google/flan-t5-small 6
EleutherAI/gpt-neo-125m 6
google/mobilenet_v2_1.0_224 6
facebook/nllb-200-distilled-600M 3
Helsinki-NLP/opus-mt-de-en 2
Helsinki-NLP/opus-mt-en-es 2
Helsinki-NLP/opus-mt-en-fr 2
Helsinki-NLP/opus-mt-en-ro 2
Helsinki-NLP/opus-mt-es-en 2
EleutherAI/pythia-160m 6
EleutherAI/pythia-70m 6
microsoft/resnet-18 6
microsoft/resnet-50 6
FacebookAI/roberta-base 4
deepset/roberta-base-squad2 6
FacebookAI/roberta-large-mnli 4
microsoft/swin-tiny-patch4-window7-224 6
google-t5/t5-base 4
hf-internal-testing/tiny-random-bart 4
hf-internal-testing/tiny-random-pegasus 4
hf-internal-testing/tiny-random-roberta 4
hf-internal-testing/tiny-random-t5 4
google/vit-base-patch16-224 6
facebook/wav2vec2-base-960h 6
openai/whisper-base 6
openai/whisper-small 6
openai/whisper-tiny 6
Qwen/Qwen2.5-0.5B-Instruct 3
TinyLlama/TinyLlama-1.1B-Chat-v1.0 3
Salesforce/blip-image-captioning-base 4
Salesforce/codegen-350M-mono 4
Salesforce/codet5-small 4
facebook/convnext-tiny-224 4
microsoft/deberta-v3-base 4
facebook/deit-base-distilled-patch16-224 4
sshleifer/distilbart-cnn-12-6 2
facebook/dpr-question_encoder-single-nq-base 2
google/electra-small-discriminator 2
makenotion/notion-mcp-server 8
facebook/opt-125m 4
facebook/opt-350m 4
Helsinki-NLP/opus-mt-en-de 2
cardiffnlp/twitter-roberta-base-sentiment-latest 4
stripe/agent-toolkit 0
tinyfish-io/agentql-mcp 0
domdomegg/airtable-mcp-server 0
upstash/context7 0
exa-labs/exa-mcp-server 0
firecrawl/firecrawl-mcp-server 0
shinzo-labs/hubspot-mcp 0
ferrislucas/iterm-mcp 0
salesforcecli/mcp 5
MarkusPfundstein/mcp-obsidian 0
e2b-dev/mcp-server 0
Flux159/mcp-server-kubernetes 0
benborla/mcp-server-mysql 0
neondatabase/mcp-server-neon 0
neondatabase-labs/mcp-server-neon 0
qdrant/mcp-server-qdrant 0
BurtTheCoder/mcp-shodan 0
mongodb-js/mongodb-mcp-server 0
microsoft/playwright-mcp 0
modelcontextprotocol/servers 0
modelcontextprotocol/servers 0
modelcontextprotocol/servers 0
modelcontextprotocol/servers 0
modelcontextprotocol/servers 0
modelcontextprotocol/servers 0
modelcontextprotocol/servers 0
modelcontextprotocol/servers 0
modelcontextprotocol/servers 0
tavily-ai/tavily-mcp 0