AgentScore is for sale. View the assets and acquisition details →
low

AGENTSCORE-2026-0063

MCP package: @diagrammo/dgmo-mcp

Published 6/13/2026 · 0.2.30.2.6

@diagrammo/dgmo-mcp updated from 0.2.3 to 0.2.6. Score changed 95/100 to 90/100 (-5). Risk: LOW to LOW. 2 findings.

9590
Score
LOWLOW
Risk
ALLOW
Verdict

Findings

  • low command_injection: Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:${COPY_SCRIPT}, sanitizer:${JSON.stringify()
  • low no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: demian0311