AgentScore is for sale. View the assets and acquisition details →
high

AGENTSCORE-2026-0055

MCP package: safari-mcp

Published 5/26/2026 · 2.11.62.11.8

safari-mcp updated from 2.11.6 to 2.11.8. Score changed 70/100 to 65/100 (-5). Risk: MODERATE to ELEVATED. 4 findings.

7065
Score
MODERATEELEVATED
Risk
WARN
Verdict

Findings

  • low install_script: Package has 'postinstall' script: node scripts/postinstall.cjs || true
  • low command_injection: Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:path.join, sanitizer:codesign)
  • high unsafe_eval: Uses eval() with dynamic input
  • low no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: achiya