{"advisories":[{"id":"AGENTSCORE-2026-0135","package":"@yun520-1/heartflow","old_version":"6.7.77","new_version":"6.7.124","old_score":85,"new_score":55,"old_risk":"LOW","new_risk":"ELEVATED","findings":[{"file":"package/scripts/auto-upgrade-hourly.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"},{"file":"package/test/code-security-command-injection.test.js","type":"unsafe_eval","detail":"Uses eval() with dynamic input","severity":"high","recommendation":"Avoid eval with variables. Use JSON.parse or structured dispatch instead."},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: yun520-1","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"@yun520-1/heartflow updated from 6.7.77 to 6.7.124. Score changed 85/100 to 55/100 (-30). Risk: LOW to ELEVATED. 3 findings.","detected_at":"2026-09-28T08:50:32.01+00:00","published_at":"2026-09-28T08:50:32.248091+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0134","package":"@pushary/agent-hooks","old_version":"1.4.1","new_version":"1.7.3","old_score":85,"new_score":70,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"type":"no_repository","detail":"Package has no repository link — source code is not verifiable","severity":"medium","recommendation":"Prefer packages with public source repositories"},{"file":"package/dist/bin/pushary-setup.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"@pushary/agent-hooks updated from 1.4.1 to 1.7.3. Score changed 85/100 to 70/100 (-15). Risk: LOW to MODERATE. 2 findings.","detected_at":"2026-09-28T04:50:27.123+00:00","published_at":"2026-09-28T04:50:27.370551+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0133","package":"@snutils/snu","old_version":"0.3.4","new_version":"0.3.5","old_score":85,"new_score":65,"old_risk":"LOW","new_risk":"ELEVATED","findings":[{"type":"no_repository","detail":"Package has no repository link — source code is not verifiable","severity":"medium","recommendation":"Prefer packages with public source repositories"},{"file":"package/dist/nowsdk/NowSdkBuild.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: arnoudkooi","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"@snutils/snu updated from 0.3.4 to 0.3.5. Score changed 85/100 to 65/100 (-20). Risk: LOW to ELEVATED. 3 findings.","detected_at":"2026-09-27T23:00:59.105+00:00","published_at":"2026-09-27T23:00:59.16825+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0132","package":"@thingd/cli","old_version":"0.88.2","new_version":"0.91.0","old_score":95,"new_score":80,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"file":"package/dist/index.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"@thingd/cli updated from 0.88.2 to 0.91.0. Score changed 95/100 to 80/100 (-15). Risk: LOW to MODERATE. 1 finding.","detected_at":"2026-09-27T20:30:40.96+00:00","published_at":"2026-09-27T20:30:41.037587+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0131","package":"clawmem","old_version":"0.37.0","new_version":"0.39.0","old_score":85,"new_score":70,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"file":"package/docs/concepts/composite-scoring.md","type":"unsafe_eval","detail":"Uses eval() with dynamic input (downgraded — mitigators detected in scope: documentation_context:```\n, documentation_context:# C)","severity":"low","recommendation":"Avoid eval with variables. Use JSON.parse or structured dispatch instead.","mitigators_detected":["```\n","# C"],"mitigation_categories":["documentation_context"],"severity_downgraded_from":"high"},{"file":"package/src/eval/vec-daemon-child.ts","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: yoloshii","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"clawmem updated from 0.37.0 to 0.39.0. Score changed 85/100 to 70/100 (-15). Risk: LOW to MODERATE. 3 findings.","detected_at":"2026-09-27T18:40:29.247+00:00","published_at":"2026-09-27T18:40:29.528604+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0130","package":"@yun520-1/heartflow","old_version":"6.7.70","new_version":"6.7.77","old_score":95,"new_score":85,"old_risk":"LOW","new_risk":"LOW","findings":[{"file":"package/src/index.js","type":"unsafe_eval","detail":"Uses eval() with dynamic input (downgraded — mitigators detected in scope: sanitizer:execFile)","severity":"low","recommendation":"Avoid eval with variables. Use JSON.parse or structured dispatch instead.","mitigators_detected":["execFile"],"mitigation_categories":["sanitizer"],"severity_downgraded_from":"high"},{"file":"package/src/mcp-server.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:${PORT}, test_fixture:test()","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":["${PORT}","test(",".test.js"],"mitigation_categories":["sanitizer","test_fixture"],"severity_downgraded_from":"high"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: yun520-1","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"@yun520-1/heartflow updated from 6.7.70 to 6.7.77. Score changed 95/100 to 85/100 (-10). Risk: LOW to LOW. 3 findings.","detected_at":"2026-09-22T12:46:20.223+00:00","published_at":"2026-09-22T12:46:20.282689+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0129","package":"@djolex999/vir-cli","old_version":"0.17.1","new_version":"0.17.1","old_score":95,"new_score":75,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"file":"package/dist/pipeline/run.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: djolex999","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"@djolex999/vir-cli updated from 0.17.1 to 0.17.1. Score changed 95/100 to 75/100 (-20). Risk: LOW to MODERATE. 2 findings.","detected_at":"2026-09-16T19:00:48.309+00:00","published_at":"2026-09-16T19:00:48.595707+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-25","findings":{"command_injection":{"verdict":"false_positive","reviewed":"2026-09-25","note":"All matches are SQLite db.exec calls with constant table names, not shell commands."}}}},{"id":"AGENTSCORE-2026-0128","package":"@bashbop/otito","old_version":"1.9.2","new_version":"1.10.0","old_score":75,"new_score":65,"old_risk":"MODERATE","new_risk":"ELEVATED","findings":[{"type":"install_script","detail":"Package has 'postinstall' script: node scripts/postinstall.mjs","severity":"low","recommendation":"Install script detected but contains no obvious network calls"},{"file":"package/evals/fixtures/gate-node/changes/secret-content/src/greeting.js","type":"hardcoded_secret","detail":"Hardcoded secret found (AWS key, OpenAI key, GitHub token, or npm token) (downgraded — mitigators detected in scope: test_fixture:fixture)","severity":"medium","recommendation":"Remove hardcoded secrets. Use environment variables instead.","mitigators_detected":["fixture"],"mitigation_categories":["test_fixture"],"severity_downgraded_from":"critical"},{"file":"package/src/lib/tools.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"@bashbop/otito updated from 1.9.2 to 1.10.0. Score changed 75/100 to 65/100 (-10). Risk: MODERATE to ELEVATED. 3 findings.","detected_at":"2026-09-15T09:20:28.367+00:00","published_at":"2026-09-15T09:20:28.629555+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-25","findings":{"command_injection":{"verdict":"false_positive","reviewed":"2026-09-25","note":"The value is wrapped in a correct POSIX single-quote escaper, and every caller passes a constant tool name."}}}},{"id":"AGENTSCORE-2026-0127","package":"aiterm-mcp","old_version":"0.37.1","new_version":"0.37.2","old_score":95,"new_score":80,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"file":"package/dist/windows-codex-setup.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"aiterm-mcp updated from 0.37.1 to 0.37.2. Score changed 95/100 to 80/100 (-15). Risk: LOW to MODERATE. 1 finding.","detected_at":"2026-09-13T15:30:49.846+00:00","published_at":"2026-09-13T15:30:49.90815+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-24","findings":{"command_injection":{"verdict":"false_positive","reviewed":"2026-09-24","note":"Both matches are argument-array spawnSync calls with no shell, and the session name is validated against a strict pattern."}}}},{"id":"AGENTSCORE-2026-0126","package":"@golproductions/envie","old_version":"0.7.2","new_version":"0.8.0","old_score":95,"new_score":80,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"file":"package/src/translate.cjs","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"@golproductions/envie updated from 0.7.2 to 0.8.0. Score changed 95/100 to 80/100 (-15). Risk: LOW to MODERATE. 1 finding.","detected_at":"2026-09-12T12:58:19.765+00:00","published_at":"2026-09-12T12:58:19.829156+00:00","review":{"status":"confirmed","reviewed_at":"2026-09-24","findings":{"command_injection":{"verdict":"confirmed","reviewed":"2026-09-24","note":"File paths supplied by the model reach double-quoted shell strings in src/render.cjs, where $(...) still expands. Affects 0.8.0 to 0.8.5; fixed in 0.8.6."}}}},{"id":"AGENTSCORE-2026-0125","package":"trace-mcp","old_version":"3.20.0","new_version":"3.25.0","old_score":85,"new_score":80,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"type":"install_script","detail":"Package has 'postinstall' script: node scripts/preflight-native.mjs && node scripts/postinstall-app.mjs && node scripts/postinstall-control-plane.mjs","severity":"low","recommendation":"Install script detected but contains no obvious network calls"},{"type":"excessive_dependencies","detail":"Package has 21 runtime dependencies (high attack surface)","severity":"medium","recommendation":"Prefer packages with fewer dependencies"},{"file":"package/dist/cli.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:.exec(\n            `CREATE, sanitizer:db.exec()","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":[".exec(\n            `CREATE","db.exec(","${JSON.stringify(","test("],"mitigation_categories":["sanitizer","test_fixture"],"severity_downgraded_from":"high"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"trace-mcp updated from 3.20.0 to 3.25.0. Score changed 85/100 to 80/100 (-5). Risk: LOW to MODERATE. 3 findings.","detected_at":"2026-09-12T03:10:30.708+00:00","published_at":"2026-09-12T03:10:30.970203+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0124","package":"summer-engine","old_version":"2.8.2","new_version":"3.0.0","old_score":75,"new_score":55,"old_risk":"MODERATE","new_risk":"ELEVATED","findings":[{"file":"package/dist/cli/commands/install.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"},{"file":"package/dist/core/registry-search.js","type":"unsafe_eval","detail":"Uses eval() with dynamic input","severity":"high","recommendation":"Avoid eval with variables. Use JSON.parse or structured dispatch instead."},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: summer-engine","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"summer-engine updated from 2.8.2 to 3.0.0. Score changed 75/100 to 55/100 (-20). Risk: MODERATE to ELEVATED. 3 findings.","detected_at":"2026-09-11T04:38:18.03+00:00","published_at":"2026-09-11T04:38:18.090325+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-25","findings":{"command_injection":{"verdict":"false_positive","reviewed":"2026-09-25","note":"The match is in an operator-run install command that no MCP tool reaches."},"unsafe_eval":{"verdict":"by_design","reviewed":"2026-09-25","note":"The match is a comment. The package runs caller-supplied scripts in its editor by design."}}}},{"id":"AGENTSCORE-2026-0123","package":"hive-intelligence","old_version":"1.5.3","new_version":"1.6.0","old_score":85,"new_score":70,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"type":"excessive_dependencies","detail":"Package has 25 runtime dependencies (high attack surface)","severity":"medium","recommendation":"Prefer packages with fewer dependencies"},{"file":"package/build/open-CAEDG67G.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"hive-intelligence updated from 1.5.3 to 1.6.0. Score changed 85/100 to 70/100 (-15). Risk: LOW to MODERATE. 2 findings.","detected_at":"2026-09-10T05:30:41.807+00:00","published_at":"2026-09-10T05:30:42.065891+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-25","findings":{"command_injection":{"verdict":"false_positive","reviewed":"2026-09-25","note":"The URL comes from a fixed four-entry map, and an unknown key exits before any command runs."}}}},{"id":"AGENTSCORE-2026-0122","package":"execbro","old_version":"2.9.8","new_version":"2.11.0","old_score":100,"new_score":90,"old_risk":"LOW","new_risk":"LOW","findings":[{"file":"package/build/__tests__/unit/inputTarget.test.js","type":"unsafe_eval","detail":"Uses eval() with dynamic input (downgraded — mitigators detected in scope: test_fixture:it()","severity":"low","recommendation":"Avoid eval with variables. Use JSON.parse or structured dispatch instead.","mitigators_detected":["it("],"mitigation_categories":["test_fixture"],"severity_downgraded_from":"high"},{"file":"package/build/core/ocr.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:spawn(pythonPath, [)","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":["spawn(pythonPath, ["],"mitigation_categories":["sanitizer"],"severity_downgraded_from":"high"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"execbro updated from 2.9.8 to 2.11.0. Score changed 100/100 to 90/100 (-10). Risk: LOW to LOW. 2 findings.","detected_at":"2026-09-09T15:00:51.739+00:00","published_at":"2026-09-09T15:00:52.728787+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0121","package":"ucn","old_version":"5.3.3","new_version":"5.3.4","old_score":95,"new_score":75,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"file":"package/core/stacktrace.js","type":"unsafe_eval","detail":"Uses eval() with dynamic input","severity":"high","recommendation":"Avoid eval with variables. Use JSON.parse or structured dispatch instead."},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: mleoca","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"ucn updated from 5.3.3 to 5.3.4. Score changed 95/100 to 75/100 (-20). Risk: LOW to MODERATE. 2 findings.","detected_at":"2026-09-07T11:20:42.752+00:00","published_at":"2026-09-07T11:20:42.811529+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-25","findings":{"unsafe_eval":{"verdict":"false_positive","reviewed":"2026-09-25","note":"There is no eval call in the package. The matches are comments and patterns that detect eval in code it analyses."}}}},{"id":"AGENTSCORE-2026-0120","package":"google-tools-mcp","old_version":"2.0.0","new_version":"3.4.5","old_score":95,"new_score":85,"old_risk":"LOW","new_risk":"LOW","findings":[{"type":"excessive_dependencies","detail":"Package has 21 runtime dependencies (high attack surface)","severity":"medium","recommendation":"Prefer packages with fewer dependencies"},{"file":"package/dist/setup.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:path.join)","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":["path.join"],"mitigation_categories":["sanitizer"],"severity_downgraded_from":"high"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"google-tools-mcp updated from 2.0.0 to 3.4.5. Score changed 95/100 to 85/100 (-10). Risk: LOW to LOW. 2 findings.","detected_at":"2026-09-05T15:52:20.029+00:00","published_at":"2026-09-05T15:52:20.086653+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0119","package":"@yawlabs/mcp","old_version":"0.79.1","new_version":"0.79.2","old_score":95,"new_score":75,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"type":"install_script","detail":"Package has 'preinstall' script: node -e \"const major=Number(process.versions.node.split('.')[0]);if(major<20){console.error('@yawlabs/mcp requires Node 20 or newer; this is Node '+process.versions.node+'. Upgrade Node, then re-run t","severity":"high","recommendation":"Review the install script for network calls or code execution"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: jeffyaw","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"@yawlabs/mcp updated from 0.79.1 to 0.79.2. Score changed 95/100 to 75/100 (-20). Risk: LOW to MODERATE. 2 findings.","detected_at":"2026-09-03T00:46:17.007+00:00","published_at":"2026-09-03T00:46:17.080087+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-25","findings":{"install_script":{"verdict":"false_positive","reviewed":"2026-09-25","note":"The preinstall script only checks the Node.js version. It makes no network calls and writes no files."}}}},{"id":"AGENTSCORE-2026-0118","package":"axm.sh","old_version":"0.28.2","new_version":"0.28.4","old_score":100,"new_score":90,"old_risk":"LOW","new_risk":"LOW","findings":[{"type":"excessive_dependencies","detail":"Package has 23 runtime dependencies (high attack surface)","severity":"medium","recommendation":"Prefer packages with fewer dependencies"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"axm.sh updated from 0.28.2 to 0.28.4. Score changed 100/100 to 90/100 (-10). Risk: LOW to LOW. 1 finding.","detected_at":"2026-09-02T10:40:35.787+00:00","published_at":"2026-09-02T10:40:35.843218+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0117","package":"@agent360/browser-mcp","old_version":"1.25.0","new_version":"1.28.1","old_score":90,"new_score":75,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"file":"package/index.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: glouv","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"@agent360/browser-mcp updated from 1.25.0 to 1.28.1. Score changed 90/100 to 75/100 (-15). Risk: LOW to MODERATE. 2 findings.","detected_at":"2026-09-02T06:46:21.729+00:00","published_at":"2026-09-02T06:46:21.799608+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-24","findings":{"command_injection":{"verdict":"false_positive","reviewed":"2026-09-24","note":"The interpolated values are process IDs, parsed with Number() and checked as finite. Integers only."}}}},{"id":"AGENTSCORE-2026-0116","package":"@sidebutton/server","old_version":"1.5.5","new_version":"1.5.9","old_score":90,"new_score":75,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"file":"package/dashboard/assets/index-CsPS9ETx.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: maxsv","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":["sidebutton"],"verdict":"warn","severity":"high","summary":"@sidebutton/server updated from 1.5.5 to 1.5.9. Score changed 90/100 to 75/100 (-15). Risk: LOW to MODERATE. 2 findings.","detected_at":"2026-09-02T04:30:37.159+00:00","published_at":"2026-09-02T04:30:37.426507+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-24","findings":{"command_injection":{"verdict":"false_positive","reviewed":"2026-09-24","note":"One match is the word \"spawn\" in a log message; the other opens a URL returned by the vendor's own sign-in service."}}}},{"id":"AGENTSCORE-2026-0115","package":"@mrrlin-dev/external-agents","old_version":"0.47.0","new_version":"0.59.0","old_score":85,"new_score":75,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"type":"install_script","detail":"Package has 'postinstall' script: node scripts/postinstall-banner.mjs || true","severity":"low","recommendation":"Install script detected but contains no obvious network calls"},{"file":"package/lib/dispatch.progress.test.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:spawn(process.execPath, [, sanitizer:path.join)","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":["spawn(process.execPath, [","path.join","${JSON.stringify(","test(","fixture"],"mitigation_categories":["sanitizer","test_fixture"],"severity_downgraded_from":"high"},{"file":"package/lib/failure-log.test.js","type":"hardcoded_secret","detail":"Hardcoded secret found (AWS key, OpenAI key, GitHub token, or npm token) (downgraded — mitigators detected in scope: test_fixture:test(, test_fixture:abcdef)","severity":"medium","recommendation":"Remove hardcoded secrets. Use environment variables instead.","mitigators_detected":["test(","abcdef"],"mitigation_categories":["test_fixture"],"severity_downgraded_from":"critical"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: aiuxsolutions","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"@mrrlin-dev/external-agents updated from 0.47.0 to 0.59.0. Score changed 85/100 to 75/100 (-10). Risk: LOW to MODERATE. 4 findings.","detected_at":"2026-09-01T21:30:38.191+00:00","published_at":"2026-09-01T21:30:38.482256+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0114","package":"slashvibe-mcp","old_version":"0.8.18","new_version":"0.8.21","old_score":100,"new_score":95,"old_risk":"LOW","new_risk":"LOW","findings":[{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: brightseth","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"slashvibe-mcp updated from 0.8.18 to 0.8.21. Score changed 100/100 to 95/100 (-5). Risk: LOW to LOW. 1 finding.","detected_at":"2026-09-01T01:40:24.872+00:00","published_at":"2026-09-01T01:40:25.150747+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0113","package":"@cyanheads/git-mcp-server","old_version":"2.15.1","new_version":"2.15.3","old_score":95,"new_score":75,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"file":"package/dist/index.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: cyanheads","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"@cyanheads/git-mcp-server updated from 2.15.1 to 2.15.3. Score changed 95/100 to 75/100 (-20). Risk: LOW to MODERATE. 2 findings.","detected_at":"2026-08-29T20:10:29.957+00:00","published_at":"2026-08-29T20:10:30.23142+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-25","findings":{"command_injection":{"verdict":"false_positive","reviewed":"2026-09-25","note":"Both matches are in a bundled system-metrics library, fed by sanitised local interface names. The git tools use argument arrays."}}}},{"id":"AGENTSCORE-2026-0112","package":"hive-intelligence","old_version":"1.3.0","new_version":"1.5.2","old_score":90,"new_score":85,"old_risk":"LOW","new_risk":"LOW","findings":[{"type":"excessive_dependencies","detail":"Package has 27 runtime dependencies (high attack surface)","severity":"medium","recommendation":"Prefer packages with fewer dependencies"},{"file":"package/build/chunk-GB4XMTDE.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:${REGISTRY_PACKAGE})","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":["${REGISTRY_PACKAGE}"],"mitigation_categories":["sanitizer"],"severity_downgraded_from":"high"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"hive-intelligence updated from 1.3.0 to 1.5.2. Score changed 90/100 to 85/100 (-5). Risk: LOW to LOW. 2 findings.","detected_at":"2026-08-29T18:00:51.481+00:00","published_at":"2026-08-29T18:00:51.796899+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0111","package":"md-redline","old_version":"0.8.3","new_version":"0.9.0","old_score":75,"new_score":65,"old_risk":"MODERATE","new_risk":"ELEVATED","findings":[{"type":"excessive_dependencies","detail":"Package has 23 runtime dependencies (high attack surface)","severity":"medium","recommendation":"Prefer packages with fewer dependencies"},{"file":"package/bin/server-control.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: dejuknow","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"md-redline updated from 0.8.3 to 0.9.0. Score changed 75/100 to 65/100 (-10). Risk: MODERATE to ELEVATED. 3 findings.","detected_at":"2026-08-28T21:28:19.813+00:00","published_at":"2026-08-28T21:28:19.872927+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-25","findings":{"command_injection":{"verdict":"false_positive","reviewed":"2026-09-25","note":"The process ID comes from the operating system's own output for a validated local port."}}}},{"id":"AGENTSCORE-2026-0110","package":"@osfactory/har","old_version":"0.64.3","new_version":"1.0.0","old_score":90,"new_score":75,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"type":"install_script","detail":"Package has 'postinstall' script: node scripts/ensure-telemetry-default.cjs","severity":"low","recommendation":"Install script detected but contains no obvious network calls"},{"file":"package/dist/index.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"@osfactory/har updated from 0.64.3 to 1.0.0. Score changed 90/100 to 75/100 (-15). Risk: LOW to MODERATE. 2 findings.","detected_at":"2026-08-28T13:24:18.531+00:00","published_at":"2026-08-28T13:24:18.604314+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-24","findings":{"command_injection":{"verdict":"false_positive","reviewed":"2026-09-24","note":"The exec wrapper uses execFileSync with no shell, and the interpolated tool names are literals."}}}},{"id":"AGENTSCORE-2026-0109","package":"crawlforge-mcp-server","old_version":"5.0.1","new_version":"5.1.0","old_score":90,"new_score":80,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"type":"install_script","detail":"Package has 'postinstall' script: echo '\nCrawlForge MCP Server installed!\n\nQuick start: run \"npx crawlforge init\" to configure your API key, install skills, and register the MCP server with your AI clients.\nOr run \"npx crawlforge-setu","severity":"low","recommendation":"Install script detected but contains no obvious network calls"},{"type":"excessive_dependencies","detail":"Package has 21 runtime dependencies (high attack surface)","severity":"medium","recommendation":"Prefer packages with fewer dependencies"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: slacey75","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"crawlforge-mcp-server updated from 5.0.1 to 5.1.0. Score changed 90/100 to 80/100 (-10). Risk: LOW to MODERATE. 3 findings.","detected_at":"2026-08-26T07:20:26.18+00:00","published_at":"2026-08-26T07:20:26.251578+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0108","package":"browse-ai","old_version":"0.3.2","new_version":"1.0.0","old_score":95,"new_score":60,"old_risk":"LOW","new_risk":"ELEVATED","findings":[{"type":"install_script","detail":"Package has 'postinstall' script: node -e \"console.warn('\n⚠ browse-ai is now lastsearch — https://lastsearch.ai/migrate (this bridge stops working 2026-10-31)\n')\"","severity":"high","recommendation":"Review the install script for network calls or code execution"},{"type":"no_repository","detail":"Package has no repository link — source code is not verifiable","severity":"medium","recommendation":"Prefer packages with public source repositories"},{"type":"no_license","detail":"Package has no licence specified","severity":"low","recommendation":"Unlicensed code has unclear usage rights"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: shreyassaw","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"browse-ai updated from 0.3.2 to 1.0.0. Score changed 95/100 to 60/100 (-35). Risk: LOW to ELEVATED. 4 findings.","detected_at":"2026-08-24T10:48:16.971+00:00","published_at":"2026-08-24T10:48:17.036039+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-25","findings":{"install_script":{"verdict":"false_positive","reviewed":"2026-09-25","note":"The postinstall script only prints a rename notice."}}}},{"id":"AGENTSCORE-2026-0107","package":"maxion-mcp-gateway","old_version":"16.0.10","new_version":"17.0.0","old_score":95,"new_score":75,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"type":"install_script","detail":"Package has 'postinstall' script: node scripts/install_engines.js","severity":"low","recommendation":"Install script detected but contains no obvious network calls"},{"type":"no_repository","detail":"Package has no repository link — source code is not verifiable","severity":"medium","recommendation":"Prefer packages with public source repositories"},{"type":"no_license","detail":"Package has no licence specified","severity":"low","recommendation":"Unlicensed code has unclear usage rights"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: aruuh","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"maxion-mcp-gateway updated from 16.0.10 to 17.0.0. Score changed 95/100 to 75/100 (-20). Risk: LOW to MODERATE. 4 findings.","detected_at":"2026-08-21T10:34:16.652+00:00","published_at":"2026-08-21T10:34:16.709158+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0106","package":"memorix","old_version":"1.5.0","new_version":"1.5.1","old_score":85,"new_score":80,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"type":"excessive_dependencies","detail":"Package has 23 runtime dependencies (high attack surface)","severity":"medium","recommendation":"Prefer packages with fewer dependencies"},{"file":"package/dist/cli/index.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:.exec(`BEGIN, test_fixture:test()","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":[".exec(`BEGIN","test("],"mitigation_categories":["sanitizer","test_fixture"],"severity_downgraded_from":"high"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: avids2","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"memorix updated from 1.5.0 to 1.5.1. Score changed 85/100 to 80/100 (-5). Risk: LOW to MODERATE. 3 findings.","detected_at":"2026-08-16T16:04:19.901+00:00","published_at":"2026-08-16T16:04:19.967743+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0105","package":"prism-mcp-server","old_version":"20.8.1","new_version":"20.11.1","old_score":90,"new_score":70,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"type":"install_script","detail":"Package has 'postinstall' script: node -e \"import('./dist/postinstall.js').catch(()=>{})\"","severity":"high","recommendation":"Review the install script for network calls or code execution"},{"type":"excessive_dependencies","detail":"Package has 26 runtime dependencies (high attack surface)","severity":"medium","recommendation":"Prefer packages with fewer dependencies"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"prism-mcp-server updated from 20.8.1 to 20.11.1. Score changed 90/100 to 70/100 (-20). Risk: LOW to MODERATE. 2 findings.","detected_at":"2026-08-14T02:40:37.499+00:00","published_at":"2026-08-14T02:40:37.577748+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-25","findings":{"install_script":{"verdict":"by_design","reviewed":"2026-09-25","note":"The install script adds a hook to Claude Code and Codex settings that runs on every prompt and routes it to the package's own CLI. It makes no network calls. This is intended behaviour, but the README does not say that npm install edits those settings files."}}}},{"id":"AGENTSCORE-2026-0104","package":"@iris-eval/mcp-server","old_version":"0.4.5","new_version":"0.5.0","old_score":100,"new_score":95,"old_risk":"LOW","new_risk":"LOW","findings":[{"file":"package/dist/storage/migrations/005-normalize-created-at.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:.exec(`\n      UPDATE, sanitizer:db.exec()","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":[".exec(`\n      UPDATE","db.exec("],"mitigation_categories":["sanitizer"],"severity_downgraded_from":"high"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"@iris-eval/mcp-server updated from 0.4.5 to 0.5.0. Score changed 100/100 to 95/100 (-5). Risk: LOW to LOW. 1 finding.","detected_at":"2026-08-13T07:01:00.004+00:00","published_at":"2026-08-13T07:01:00.093907+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0103","package":"comfyui-mcp","old_version":"0.51.24","new_version":"0.51.25","old_score":95,"new_score":90,"old_risk":"LOW","new_risk":"LOW","findings":[{"type":"install_script","detail":"Package has 'postinstall' script: node scripts/postinstall.mjs","severity":"low","recommendation":"Install script detected but contains no obvious network calls"},{"file":"package/dist/services/ai-toolkit.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:${JSON.stringify()","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":["${JSON.stringify("],"mitigation_categories":["sanitizer"],"severity_downgraded_from":"high"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"comfyui-mcp updated from 0.51.24 to 0.51.25. Score changed 95/100 to 90/100 (-5). Risk: LOW to LOW. 2 findings.","detected_at":"2026-08-13T06:42:16.863+00:00","published_at":"2026-08-13T06:42:16.923178+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0102","package":"memorix","old_version":"1.4.2","new_version":"1.4.3","old_score":85,"new_score":80,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"type":"excessive_dependencies","detail":"Package has 23 runtime dependencies (high attack surface)","severity":"medium","recommendation":"Prefer packages with fewer dependencies"},{"file":"package/dist/cli/index.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:.exec(`BEGIN, test_fixture:test()","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":[".exec(`BEGIN","test("],"mitigation_categories":["sanitizer","test_fixture"],"severity_downgraded_from":"high"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: avids2","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"memorix updated from 1.4.2 to 1.4.3. Score changed 85/100 to 80/100 (-5). Risk: LOW to MODERATE. 3 findings.","detected_at":"2026-08-13T00:10:40.441+00:00","published_at":"2026-08-13T00:10:40.533344+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0101","package":"sverklo","old_version":"0.29.4","new_version":"0.29.5","old_score":100,"new_score":60,"old_risk":"LOW","new_risk":"ELEVATED","findings":[{"file":"package/dist/src/audit-diff/diff-parser.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"},{"file":"package/dist/src/search/investigate.js","type":"unsafe_eval","detail":"Uses eval() with dynamic input","severity":"high","recommendation":"Avoid eval with variables. Use JSON.parse or structured dispatch instead."}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"sverklo updated from 0.29.4 to 0.29.5. Score changed 100/100 to 60/100 (-40). Risk: LOW to ELEVATED. 2 findings.","detected_at":"2026-08-12T15:50:35.485+00:00","published_at":"2026-08-12T15:50:35.755257+00:00","review":{"status":"partial","reviewed_at":"2026-09-25","findings":{"unsafe_eval":{"verdict":"false_positive","reviewed":"2026-09-25","note":"The match is a comment, and the package makes no call to eval or similar on any input."}}}},{"id":"AGENTSCORE-2026-0100","package":"vexp-cli","old_version":"2.5.0","new_version":"2.5.3","old_score":90,"new_score":80,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"type":"no_repository","detail":"Package has no repository link — source code is not verifiable","severity":"medium","recommendation":"Prefer packages with public source repositories"},{"file":"package/dist/mcp-supervisor.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:spawn(\"node\", [, sanitizer:path.join)","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":["spawn(\"node\", [","path.join"],"mitigation_categories":["sanitizer"],"severity_downgraded_from":"high"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: vexp","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"vexp-cli updated from 2.5.0 to 2.5.3. Score changed 90/100 to 80/100 (-10). Risk: LOW to MODERATE. 3 findings.","detected_at":"2026-08-10T20:40:36.216+00:00","published_at":"2026-08-10T20:40:36.292303+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0099","package":"real-browser-mcp-server","old_version":"2.2.6","new_version":"3.2.7","old_score":80,"new_score":60,"old_risk":"MODERATE","new_risk":"ELEVATED","findings":[{"type":"install_script","detail":"Package has 'postinstall' script: patchright install chromium","severity":"low","recommendation":"Install script detected but contains no obvious network calls"},{"type":"no_repository","detail":"Package has no repository link — source code is not verifiable","severity":"medium","recommendation":"Prefer packages with public source repositories"},{"file":"package/dist/src/mcp/handlers/network-extractors.js","type":"unsafe_eval","detail":"Uses eval() with dynamic input","severity":"high","recommendation":"Avoid eval with variables. Use JSON.parse or structured dispatch instead."},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: codeiva","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"real-browser-mcp-server updated from 2.2.6 to 3.2.7. Score changed 80/100 to 60/100 (-20). Risk: MODERATE to ELEVATED. 4 findings.","detected_at":"2026-08-10T04:40:36.461+00:00","published_at":"2026-08-10T04:40:36.531135+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-25","findings":{"unsafe_eval":{"verdict":"false_positive","reviewed":"2026-09-25","note":"\"$eval\" here is a browser automation method that takes a page selector and a fixed function, not a call to JavaScript's eval."}}}},{"id":"AGENTSCORE-2026-0098","package":"mojulo","old_version":"0.8.0","new_version":"1.0.0","old_score":95,"new_score":85,"old_risk":"LOW","new_risk":"LOW","findings":[{"type":"excessive_dependencies","detail":"Package has 23 runtime dependencies (high attack surface)","severity":"medium","recommendation":"Prefer packages with fewer dependencies"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: zombico","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"mojulo updated from 0.8.0 to 1.0.0. Score changed 95/100 to 85/100 (-10). Risk: LOW to LOW. 2 findings.","detected_at":"2026-08-08T00:01:05.328+00:00","published_at":"2026-08-08T00:01:05.566996+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0097","package":"beecork","old_version":"2.8.3","new_version":"2.9.0","old_score":100,"new_score":90,"old_risk":"LOW","new_risk":"LOW","findings":[{"file":"package/skeleton/bridge.mjs","type":"hardcoded_secret","detail":"Hardcoded secret found (AWS key, OpenAI key, GitHub token, or npm token) (downgraded — mitigators detected in scope: test_fixture:ABCDEF)","severity":"medium","recommendation":"Remove hardcoded secrets. Use environment variables instead.","mitigators_detected":["ABCDEF"],"mitigation_categories":["test_fixture"],"severity_downgraded_from":"critical"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"beecork updated from 2.8.3 to 2.9.0. Score changed 100/100 to 90/100 (-10). Risk: LOW to LOW. 1 finding.","detected_at":"2026-08-07T21:48:16.126+00:00","published_at":"2026-08-07T21:48:16.287824+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0096","package":"rea-agents","old_version":"2.5.0","new_version":"3.0.0","old_score":85,"new_score":80,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"type":"excessive_dependencies","detail":"Package has 26 runtime dependencies (high attack surface)","severity":"medium","recommendation":"Prefer packages with fewer dependencies"},{"file":"package/dist/hopper/BridgeLauncher.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:execFile, sanitizer:${JSON.stringify()","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":["execFile","${JSON.stringify("],"mitigation_categories":["sanitizer"],"severity_downgraded_from":"high"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: morluto","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"rea-agents updated from 2.5.0 to 3.0.0. Score changed 85/100 to 80/100 (-5). Risk: LOW to MODERATE. 3 findings.","detected_at":"2026-08-03T18:10:31.64+00:00","published_at":"2026-08-03T18:10:31.713238+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0095","package":"@pushary/agent-hooks","old_version":"0.60.0","new_version":"0.73.0","old_score":80,"new_score":70,"old_risk":"MODERATE","new_risk":"MODERATE","findings":[{"type":"no_repository","detail":"Package has no repository link — source code is not verifiable","severity":"medium","recommendation":"Prefer packages with public source repositories"},{"file":"package/dist/bin/pushary-doctor.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"@pushary/agent-hooks updated from 0.60.0 to 0.73.0. Score changed 80/100 to 70/100 (-10). Risk: MODERATE to MODERATE. 2 findings.","detected_at":"2026-08-01T01:40:34.182+00:00","published_at":"2026-08-01T01:40:34.286187+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-25","findings":{"command_injection":{"verdict":"false_positive","reviewed":"2026-09-25","note":"The values are constants, the local npm prefix, or commands from the user's own agent configuration."}}}},{"id":"AGENTSCORE-2026-0094","package":"@apso/cli","old_version":"0.21.0","new_version":"0.32.0","old_score":85,"new_score":75,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"type":"excessive_dependencies","detail":"Package has 21 runtime dependencies (high attack surface)","severity":"medium","recommendation":"Prefer packages with fewer dependencies"},{"type":"poor_description","detail":"Package has no meaningful description","severity":"low","recommendation":"Well-documented packages are more trustworthy"},{"file":"package/dist/commands/init.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:path.join, test_fixture:test()","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":["path.join","test("],"mitigation_categories":["sanitizer","test_fixture"],"severity_downgraded_from":"high"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: cultron","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"allow","severity":"low","summary":"@apso/cli updated from 0.21.0 to 0.32.0. Score changed 85/100 to 75/100 (-10). Risk: LOW to MODERATE. 4 findings.","detected_at":"2026-07-31T16:10:36.211+00:00","published_at":"2026-07-31T16:10:36.509866+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0093","package":"@firfi/huly-mcp","old_version":"0.44.7","new_version":"0.47.0","old_score":80,"new_score":60,"old_risk":"MODERATE","new_risk":"ELEVATED","findings":[{"type":"excessive_dependencies","detail":"Package has 21 runtime dependencies (high attack surface)","severity":"medium","recommendation":"Prefer packages with fewer dependencies"},{"file":"package/dist/index.cjs","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:.exec(`\n      PRAGMA, sanitizer:db.exec()","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":[".exec(`\n      PRAGMA","db.exec(","${VERSION2}"],"mitigation_categories":["sanitizer"],"severity_downgraded_from":"high"},{"file":"package/dist/index.cjs","type":"unsafe_eval","detail":"Uses eval() with dynamic input","severity":"high","recommendation":"Avoid eval with variables. Use JSON.parse or structured dispatch instead."},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: firfi","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"@firfi/huly-mcp updated from 0.44.7 to 0.47.0. Score changed 80/100 to 60/100 (-20). Risk: MODERATE to ELEVATED. 4 findings.","detected_at":"2026-07-31T14:50:38.929+00:00","published_at":"2026-07-31T14:50:39.032062+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-24","findings":{"unsafe_eval":{"verdict":"false_positive","reviewed":"2026-09-24","note":"All matches are method definitions named eval in a bundled runtime, not calls to the global eval."}}}},{"id":"AGENTSCORE-2026-0092","package":"@mentu/metamcp","old_version":"0.4.1","new_version":"0.6.0","old_score":90,"new_score":75,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"file":"package/dist/oauth-provider.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: rashidazarang","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"@mentu/metamcp updated from 0.4.1 to 0.6.0. Score changed 90/100 to 75/100 (-15). Risk: LOW to MODERATE. 2 findings.","detected_at":"2026-07-30T02:04:15.796+00:00","published_at":"2026-07-30T02:04:15.853073+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0091","package":"code-auditor-mcp","old_version":"3.1.1","new_version":"3.4.7","old_score":70,"new_score":55,"old_risk":"MODERATE","new_risk":"ELEVATED","findings":[{"file":"package/dist/churn/churnExtractor.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"},{"file":"package/dist/cli.js","type":"unsafe_eval","detail":"Uses eval() with dynamic input","severity":"high","recommendation":"Avoid eval with variables. Use JSON.parse or structured dispatch instead."},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: bhammond","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"code-auditor-mcp updated from 3.1.1 to 3.4.7. Score changed 70/100 to 55/100 (-15). Risk: MODERATE to ELEVATED. 3 findings.","detected_at":"2026-07-29T09:20:32.837+00:00","published_at":"2026-07-29T09:20:32.902637+00:00","review":{"status":"confirmed","reviewed_at":"2026-09-25","findings":{"command_injection":{"verdict":"confirmed","reviewed":"2026-09-24","note":"The audit tool's git ref argument is interpolated unvalidated into a shell command in dist/auditRunner.js. Affects 3.0.0 to 4.0.x; fixed in 4.1.0."},"unsafe_eval":{"verdict":"false_positive","reviewed":"2026-09-25","note":"The match is the text eval($$$) inside a code-search rule example, not a call to eval."}}}},{"id":"AGENTSCORE-2026-0090","package":"safari-mcp","old_version":"2.15.8","new_version":"2.15.9","old_score":70,"new_score":65,"old_risk":"MODERATE","new_risk":"ELEVATED","findings":[{"type":"install_script","detail":"Package has 'postinstall' script: node scripts/postinstall.cjs || true","severity":"low","recommendation":"Install script detected but contains no obvious network calls"},{"file":"package/scripts/postinstall.cjs","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:path.join, sanitizer:${STABLE_ID})","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":["path.join","${STABLE_ID}","codesign"],"mitigation_categories":["sanitizer"],"severity_downgraded_from":"high"},{"file":"package/extension/background.js","type":"unsafe_eval","detail":"Uses eval() with dynamic input","severity":"high","recommendation":"Avoid eval with variables. Use JSON.parse or structured dispatch instead."},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: achiya","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"safari-mcp updated from 2.15.8 to 2.15.9. Score changed 70/100 to 65/100 (-5). Risk: MODERATE to ELEVATED. 4 findings.","detected_at":"2026-07-28T16:04:16.901+00:00","published_at":"2026-07-28T16:04:16.961083+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-25","findings":{"unsafe_eval":{"verdict":"by_design","reviewed":"2026-09-25","note":"The matched line is a comment. The safari_evaluate tool runs JavaScript in the page by design."}}}},{"id":"AGENTSCORE-2026-0089","package":"ori-memory","old_version":"0.5.5","new_version":"0.6.0","old_score":95,"new_score":75,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"file":"package/dist/cli/repl.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: aayoawoyemi","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"ori-memory updated from 0.5.5 to 0.6.0. Score changed 95/100 to 75/100 (-20). Risk: LOW to MODERATE. 2 findings.","detected_at":"2026-07-27T21:42:16.882+00:00","published_at":"2026-07-27T21:42:16.944877+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-25","findings":{"command_injection":{"verdict":"false_positive","reviewed":"2026-09-25","note":"The interpolated path is a hard-coded constant left over from development, not input."}}}},{"id":"AGENTSCORE-2026-0088","package":"real-browser-mcp-server","old_version":"2.0.10","new_version":"2.2.2","old_score":85,"new_score":60,"old_risk":"LOW","new_risk":"ELEVATED","findings":[{"type":"install_script","detail":"Package has 'postinstall' script: node scripts/setup-browser.js","severity":"low","recommendation":"Install script detected but contains no obvious network calls"},{"type":"no_repository","detail":"Package has no repository link — source code is not verifiable","severity":"medium","recommendation":"Prefer packages with public source repositories"},{"file":"package/dist/src/mcp/handlers/network-extractors.js","type":"unsafe_eval","detail":"Uses eval() with dynamic input","severity":"high","recommendation":"Avoid eval with variables. Use JSON.parse or structured dispatch instead."},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: codeiva","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"real-browser-mcp-server updated from 2.0.10 to 2.2.2. Score changed 85/100 to 60/100 (-25). Risk: LOW to ELEVATED. 4 findings.","detected_at":"2026-07-24T23:40:32.115+00:00","published_at":"2026-07-24T23:40:32.21341+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0087","package":"code-auditor-mcp","old_version":"3.0.0","new_version":"3.1.1","old_score":90,"new_score":70,"old_risk":"LOW","new_risk":"MODERATE","findings":[{"file":"package/dist/auditRunner.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:path.resolve, sanitizer:${handoffRemaining.length})","severity":"low","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives","mitigators_detected":["path.resolve","${handoffRemaining.length}"],"mitigation_categories":["sanitizer"],"severity_downgraded_from":"high"},{"file":"package/dist/cli.js","type":"unsafe_eval","detail":"Uses eval() with dynamic input","severity":"high","recommendation":"Avoid eval with variables. Use JSON.parse or structured dispatch instead."},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: bhammond","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"code-auditor-mcp updated from 3.0.0 to 3.1.1. Score changed 90/100 to 70/100 (-20). Risk: LOW to MODERATE. 3 findings.","detected_at":"2026-07-24T00:40:35.127+00:00","published_at":"2026-07-24T00:40:35.371657+00:00","review":{"status":"unreviewed","reviewed_at":null,"findings":{}}},{"id":"AGENTSCORE-2026-0086","package":"@respira/wordpress-mcp-server","old_version":"7.6.1","new_version":"7.6.2","old_score":75,"new_score":65,"old_risk":"MODERATE","new_risk":"ELEVATED","findings":[{"type":"no_repository","detail":"Package has no repository link — source code is not verifiable","severity":"medium","recommendation":"Prefer packages with public source repositories"},{"file":"package/dist/agent-signature.js","type":"command_injection","detail":"Potential command injection: shell execution with template literal input","severity":"high","recommendation":"Sanitise all inputs to shell commands or use parameterised alternatives"},{"type":"no_provenance","detail":"Package is not published with provenance attestations or trusted publishing. Published by: mihai_respira","severity":"low","recommendation":"Enable npm provenance via GitHub Actions to provide a verifiable build-to-publish chain"}],"affected_servers":[],"verdict":"warn","severity":"high","summary":"@respira/wordpress-mcp-server updated from 7.6.1 to 7.6.2. Score changed 75/100 to 65/100 (-10). Risk: MODERATE to ELEVATED. 3 findings.","detected_at":"2026-07-23T21:28:16.922+00:00","published_at":"2026-07-23T21:28:17.005088+00:00","review":{"status":"withdrawn","reviewed_at":"2026-09-25","findings":{"command_injection":{"verdict":"false_positive","reviewed":"2026-09-25","note":"The interpolated values are process IDs from the operating system."}}}}],"total":50,"feed_url":"https://agentscores.xyz/security/advisories/rss.xml"}