news aggregation
TrendRadar is a trend monitoring and news aggregation server that collects trending topics from multiple platforms and delivers curated alerts through various messaging channels. It features AI-powered filtering and analysis of news content, with support for multi-language translation and integration with messaging platforms like WeChat, Telegram, DingTalk, and email.
Deploy in 30 seconds to monitor trending news across multiple platforms without information overload Filter and receive only news matching your interests using AI-powered intelligent filtering Aggregate content from various sources and push to your preferred notification channels (WeChat, Telegram, Slack, email, etc.) Analyze trending stories with AI summaries before reading full articles Set up automated monitoring via GitHub Actions, Docker, or local deployment 1 CRITICAL✓ 1 HIGH✓ 108 MEDIUM 7 LOW
✓ CRITICAL/HIGH reflect AI-verified findings (false positives excluded) · MEDIUM/LOW/INFO are unverified scanner output
AI-verified (CRITICAL/HIGH): 2 likely real (100%) 1 false positive — excluded from CRITICAL/HIGH count above
Findings by checker · 2 high-signal, 1 mostly false-positive (hidden by default)
CHK-107 1 finding 1 likely
0% FP CHK-099 1 finding 1 likely
0% FP ▼ Show 1 checker that are mostly false positives (1 findings) 117 findings click to expand
CHK-107 Potential real secret in .env file: S3_ACCESS_KEY_ID
docker/.env
AI: likely real likely ▼
CHK-099 Potential IDOR — 'task_id' accessed without ownership check
mcp_server/tools/system.py
AI: likely real possible ▼
CHK-102 Direct SQL execution — may bypass ORM-level access controls
trendradar/storage/sqlite_mixin.py
possible ▼
CHK-125a os.remove() — file deletion — no scope constraint in docker/manage.py
docker/manage.py
possible ▼
CHK-036 [PYSEC-2026-2046] werkzeug 3.1.1 — see advisory: PYSEC-2026-2046
possible ▼
CHK-102 Direct SQL execution — may bypass ORM-level access controls
mcp_server/services/parser_service.py
possible ▼
CHK-102 Direct SQL execution — may bypass ORM-level access controls
trendradar/storage/remote.py
possible ▼
CHK-036 [PYSEC-2026-1994] urllib3 2.5.0 — see advisory: PYSEC-2026-1994
possible ▼
CHK-036 [PYSEC-2026-1996] urllib3 2.5.0 — see advisory: PYSEC-2026-1996
possible ▼
CHK-036 [PYSEC-2026-1998] urllib3 2.5.0 — see advisory: PYSEC-2026-1998
possible ▼
CHK-036 [GHSA-29vq-49wr-vm6x] werkzeug 3.1.1 — see advisory: GHSA-29vq-49wr-vm6x
possible ▼
CHK-036 [GHSA-87hc-h4r5-73f7] werkzeug 3.1.1 — see advisory: GHSA-87hc-h4r5-73f7
possible ▼
CHK-036 [GHSA-hgf8-39gv-g3f2] werkzeug 3.1.1 — see advisory: GHSA-hgf8-39gv-g3f2
possible ▼
CHK-036 [PYSEC-2026-2044] werkzeug 3.1.1 — see advisory: PYSEC-2026-2044
possible ▼
CHK-125a shutil.rmtree() — recursive directory deletion — no scope constraint in storage/remote.py
trendradar/storage/remote.py
possible ▼
CHK-125a shutil.rmtree() — recursive directory deletion — no scope constraint in storage/local.py
trendradar/storage/local.py
possible ▼
CHK-125a open() with absolute path — unrestricted file access — no scope constraint in storage/manager.py
trendradar/storage/manager.py
possible ▼
CHK-036 [GHSA-5h2m-4q8j-pqpj] fastmcp 2.12.5 — see advisory: GHSA-5h2m-4q8j-pqpj
possible ▼
CHK-036 [GHSA-c2jp-c369-7pvx] fastmcp 2.12.5 — see advisory: GHSA-c2jp-c369-7pvx
possible ▼
CHK-036 [GHSA-m8x7-r2rg-vh5g] fastmcp 2.12.5 — see advisory: GHSA-m8x7-r2rg-vh5g
possible ▼
CHK-036 [GHSA-mxxr-jv3v-6pgc] fastmcp 2.12.5 — see advisory: GHSA-mxxr-jv3v-6pgc
possible ▼
CHK-036 [GHSA-rcfx-77hg-w2wv] fastmcp 2.12.5 — see advisory: GHSA-rcfx-77hg-w2wv
possible ▼
CHK-036 [GHSA-rj5c-58rq-j5g5] fastmcp 2.12.5 — see advisory: GHSA-rj5c-58rq-j5g5
possible ▼
CHK-036 [GHSA-rww4-4w9c-7733] fastmcp 2.12.5 — see advisory: GHSA-rww4-4w9c-7733
possible ▼
CHK-036 [GHSA-vv7q-7jx5-f767] fastmcp 2.12.5 — see advisory: GHSA-vv7q-7jx5-f767
possible ▼
CHK-036 [PYSEC-2026-1364] fastmcp 2.12.5 — see advisory: PYSEC-2026-1364
possible ▼
CHK-036 [PYSEC-2026-1365] fastmcp 2.12.5 — see advisory: PYSEC-2026-1365
possible ▼
CHK-036 [PYSEC-2026-338] fastmcp 2.12.5 — see advisory: PYSEC-2026-338
possible ▼
CHK-036 [GHSA-4xpc-pv4p-pm3w] litellm 1.82.6 — see advisory: GHSA-4xpc-pv4p-pm3w
possible ▼
CHK-036 [GHSA-53mr-6c8q-9789] litellm 1.82.6 — see advisory: GHSA-53mr-6c8q-9789
possible ▼
CHK-036 [GHSA-69x8-hrgq-fjj8] litellm 1.82.6 — see advisory: GHSA-69x8-hrgq-fjj8
possible ▼
CHK-036 [GHSA-jjhc-v7c2-5hh6] litellm 1.82.6 — see advisory: GHSA-jjhc-v7c2-5hh6
possible ▼
CHK-036 [GHSA-qrc4-49gv-mv9m] litellm 1.82.6 — see advisory: GHSA-qrc4-49gv-mv9m
possible ▼
CHK-036 [GHSA-r75f-5x8p-qvmc] litellm 1.82.6 — see advisory: GHSA-r75f-5x8p-qvmc
possible ▼
CHK-036 [GHSA-v4p8-mg3p-g94g] litellm 1.82.6 — see advisory: GHSA-v4p8-mg3p-g94g
possible ▼
CHK-036 [GHSA-wpfp-gwwc-vwq6] litellm 1.82.6 — see advisory: GHSA-wpfp-gwwc-vwq6
possible ▼
CHK-036 [GHSA-wxxx-gvqv-xp7p] litellm 1.82.6 — see advisory: GHSA-wxxx-gvqv-xp7p
possible ▼
CHK-036 [GHSA-xqmj-j6mv-4862] litellm 1.82.6 — see advisory: GHSA-xqmj-j6mv-4862
possible ▼
CHK-036 [PYSEC-2026-388] litellm 1.82.6 — see advisory: PYSEC-2026-388
possible ▼
CHK-036 [PYSEC-2026-390] litellm 1.82.6 — see advisory: PYSEC-2026-390
possible ▼
CHK-036 [PYSEC-2026-391] litellm 1.82.6 — see advisory: PYSEC-2026-391
possible ▼
CHK-036 [GHSA-2fqr-mr3j-6wp8] aiohttp 3.13.3 — see advisory: GHSA-2fqr-mr3j-6wp8
possible ▼
CHK-036 [GHSA-2vrm-gr82-f7m5] aiohttp 3.13.3 — see advisory: GHSA-2vrm-gr82-f7m5
possible ▼
CHK-036 [GHSA-3wq7-rqq7-wx6j] aiohttp 3.13.3 — see advisory: GHSA-3wq7-rqq7-wx6j
possible ▼
CHK-036 [GHSA-4fvr-rgm6-gqmc] aiohttp 3.13.3 — see advisory: GHSA-4fvr-rgm6-gqmc
possible ▼
CHK-036 [GHSA-4m7w-qmgq-4wj5] aiohttp 3.13.3 — see advisory: GHSA-4m7w-qmgq-4wj5
possible ▼
CHK-036 [GHSA-63hf-3vf5-4wqf] aiohttp 3.13.3 — see advisory: GHSA-63hf-3vf5-4wqf
possible ▼
CHK-036 [GHSA-63hw-fmq6-xxg2] aiohttp 3.13.3 — see advisory: GHSA-63hw-fmq6-xxg2
possible ▼
CHK-036 [GHSA-966j-vmvw-g2g9] aiohttp 3.13.3 — see advisory: GHSA-966j-vmvw-g2g9
possible ▼
CHK-036 [GHSA-9x8q-7h8h-wcw9] aiohttp 3.13.3 — see advisory: GHSA-9x8q-7h8h-wcw9
possible ▼
CHK-036 [GHSA-c427-h43c-vf67] aiohttp 3.13.3 — see advisory: GHSA-c427-h43c-vf67
possible ▼
CHK-036 [GHSA-g3cq-j2xw-wf74] aiohttp 3.13.3 — see advisory: GHSA-g3cq-j2xw-wf74
possible ▼
CHK-036 [GHSA-hcc4-c3v8-rx92] aiohttp 3.13.3 — see advisory: GHSA-hcc4-c3v8-rx92
possible ▼
CHK-036 [GHSA-hg6j-4rv6-33pg] aiohttp 3.13.3 — see advisory: GHSA-hg6j-4rv6-33pg
possible ▼
CHK-036 [GHSA-hpj7-wq8m-9hgp] aiohttp 3.13.3 — see advisory: GHSA-hpj7-wq8m-9hgp
possible ▼
CHK-036 [GHSA-jg22-mg44-37j8] aiohttp 3.13.3 — see advisory: GHSA-jg22-mg44-37j8
possible ▼
CHK-036 [GHSA-m5qp-6w8w-w647] aiohttp 3.13.3 — see advisory: GHSA-m5qp-6w8w-w647
possible ▼
CHK-036 [GHSA-m6qw-4cw2-hm4m] aiohttp 3.13.3 — see advisory: GHSA-m6qw-4cw2-hm4m
possible ▼
CHK-036 [GHSA-mwh4-6h8g-pg8w] aiohttp 3.13.3 — see advisory: GHSA-mwh4-6h8g-pg8w
possible ▼
CHK-036 [GHSA-p998-jp59-783m] aiohttp 3.13.3 — see advisory: GHSA-p998-jp59-783m
possible ▼
CHK-036 [GHSA-w2fm-2cpv-w7v5] aiohttp 3.13.3 — see advisory: GHSA-w2fm-2cpv-w7v5
possible ▼
CHK-036 [GHSA-xcgm-r5h9-7989] aiohttp 3.13.3 — see advisory: GHSA-xcgm-r5h9-7989
possible ▼
CHK-036 [PYSEC-2026-237] aiohttp 3.13.3 — see advisory: PYSEC-2026-237
possible ▼
CHK-036 [GHSA-7432-952r-cw78] authlib 1.6.5 — see advisory: GHSA-7432-952r-cw78
possible ▼
CHK-036 [GHSA-7wc2-qxgw-g8gg] authlib 1.6.5 — see advisory: GHSA-7wc2-qxgw-g8gg
possible ▼
CHK-036 [GHSA-fg6f-75jq-6523] authlib 1.6.5 — see advisory: GHSA-fg6f-75jq-6523
possible ▼
CHK-036 [GHSA-jj8c-mmj3-mmgv] authlib 1.6.5 — see advisory: GHSA-jj8c-mmj3-mmgv
possible ▼
CHK-036 [GHSA-m344-f55w-2m6j] authlib 1.6.5 — see advisory: GHSA-m344-f55w-2m6j
possible ▼
CHK-036 [GHSA-r95x-qfjj-fjj2] authlib 1.6.5 — see advisory: GHSA-r95x-qfjj-fjj2
possible ▼
CHK-036 [GHSA-w8p2-r796-3vmq] authlib 1.6.5 — see advisory: GHSA-w8p2-r796-3vmq
possible ▼
CHK-036 [GHSA-wvwj-cvrp-7pv5] authlib 1.6.5 — see advisory: GHSA-wvwj-cvrp-7pv5
possible ▼
CHK-036 [PYSEC-2026-1201] authlib 1.6.5 — see advisory: PYSEC-2026-1201
possible ▼
CHK-036 [PYSEC-2026-188] authlib 1.6.5 — see advisory: PYSEC-2026-188
possible ▼
CHK-036 [PYSEC-2026-25] authlib 1.6.5 — see advisory: PYSEC-2026-25
possible ▼
CHK-036 [PYSEC-2026-287] authlib 1.6.5 — see advisory: PYSEC-2026-287
possible ▼
CHK-036 [GHSA-537c-gmf6-5ccf] cryptography 46.0.3 — see advisory: GHSA-537c-gmf6-5ccf
possible ▼
CHK-036 [GHSA-m959-cc7f-wv43] cryptography 46.0.3 — see advisory: GHSA-m959-cc7f-wv43
possible ▼
CHK-036 [GHSA-p423-j2cm-9vmq] cryptography 46.0.3 — see advisory: GHSA-p423-j2cm-9vmq
possible ▼
CHK-036 [GHSA-r6ph-v2qm-q3c2] cryptography 46.0.3 — see advisory: GHSA-r6ph-v2qm-q3c2
possible ▼
CHK-036 [PYSEC-2026-35] cryptography 46.0.3 — see advisory: PYSEC-2026-35
possible ▼
CHK-036 [PYSEC-2026-36] cryptography 46.0.3 — see advisory: PYSEC-2026-36
possible ▼
CHK-036 [GHSA-65pc-fj4g-8rjx] idna 3.11 — see advisory: GHSA-65pc-fj4g-8rjx
possible ▼
CHK-036 [PYSEC-2026-215] idna 3.11 — see advisory: PYSEC-2026-215
possible ▼
CHK-036 [GHSA-9h52-p55h-vw2f] mcp 1.16.0 — see advisory: GHSA-9h52-p55h-vw2f
possible ▼
CHK-036 [PYSEC-2026-1617] mcp 1.16.0 — see advisory: PYSEC-2026-1617
possible ▼
CHK-036 [GHSA-5239-wwwm-4pmq] pygments 2.19.2 — see advisory: GHSA-5239-wwwm-4pmq
possible ▼
CHK-036 [GHSA-mf9w-mj56-hr94] python-dotenv 1.1.1 — see advisory: GHSA-mf9w-mj56-hr94
possible ▼
CHK-036 [GHSA-5rvq-cxj2-64vf] python-multipart 0.0.20 — see advisory: GHSA-5rvq-cxj2-64vf
possible ▼
CHK-036 [GHSA-6jv3-5f52-599m] python-multipart 0.0.20 — see advisory: GHSA-6jv3-5f52-599m
possible ▼
CHK-036 [GHSA-mj87-hwqh-73pj] python-multipart 0.0.20 — see advisory: GHSA-mj87-hwqh-73pj
possible ▼
CHK-036 [GHSA-pp6c-gr5w-3c5g] python-multipart 0.0.20 — see advisory: GHSA-pp6c-gr5w-3c5g
possible ▼
CHK-036 [GHSA-v9pg-7xvm-68hf] python-multipart 0.0.20 — see advisory: GHSA-v9pg-7xvm-68hf
possible ▼
CHK-036 [GHSA-vffw-93wf-4j4q] python-multipart 0.0.20 — see advisory: GHSA-vffw-93wf-4j4q
possible ▼
CHK-036 [GHSA-wp53-j4wj-2cfg] python-multipart 0.0.20 — see advisory: GHSA-wp53-j4wj-2cfg
possible ▼
CHK-036 [PYSEC-2026-1852] python-multipart 0.0.20 — see advisory: PYSEC-2026-1852
possible ▼
CHK-036 [GHSA-7f5h-v6xp-fcq8] starlette 0.48.0 — see advisory: GHSA-7f5h-v6xp-fcq8
possible ▼
CHK-036 [GHSA-82w8-qh3p-5jfq] starlette 0.48.0 — see advisory: GHSA-82w8-qh3p-5jfq
possible ▼
CHK-036 [GHSA-86qp-5c8j-p5mr] starlette 0.48.0 — see advisory: GHSA-86qp-5c8j-p5mr
possible ▼
CHK-036 [GHSA-jp82-jpqv-5vv3] starlette 0.48.0 — see advisory: GHSA-jp82-jpqv-5vv3
possible ▼
CHK-036 [GHSA-wqp7-x3pw-xc5r] starlette 0.48.0 — see advisory: GHSA-wqp7-x3pw-xc5r
possible ▼
▼ Show 1 false positive (1% of this view) Last scanned: Jul 12, 2026
More servers
google-gemini/gemini-cli 85
An open-source AI agent that brings the power of Gemini directly into your terminal.
106k★
skypilot-org/skypilot 85
obra/superpowers 85
Foundational skill pack by Jesse Vincent now in anthropics/claude-plugins-official. Includes ffuf web-fuzzing/pentest skill. Partial analysis done — full hook and plugin inspection pending. tier=T2
191k★
Significant-Gravitas/AutoGPT 85
AutoGPT is the vision of accessible AI for everyone, to use and to build on. Our mission is to provide the tools, so that you can focus on what matters.
186k★
nanocoai/nanoclaw 85
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
30k★
google-gemini/gemini-cli 85
An open-source AI agent that brings the power of Gemini directly into your terminal.
106k★
Scan your entire org's MCP deployment
2,500+ repos pre-scored. 22% carry CRITICAL findings.