AGENTSCORE-2026-0010
MCP package: memorix
Published 4/23/2026 · 1.0.7 → 1.0.8
memorix updated from 1.0.7 to 1.0.8. Score changed 90/100 to 80/100 (-10). Risk: LOW to MODERATE. 3 findings.
90 → 80
Score
LOW → MODERATE
Risk
ALLOW
Verdict
Findings
- medium excessive_dependencies: Package has 22 runtime dependencies (high attack surface)
- low unsafe_eval: Uses eval() with dynamic input (downgraded — mitigators detected in scope: test_fixture:test()
- low no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: avids2