AgentScore is for sale. View the assets and acquisition details →
low

AGENTSCORE-2026-0067

MCP package: metaharness

Published 6/22/2026 · 0.1.150.2.5

metaharness updated from 0.1.15 to 0.2.5. Score changed 95/100 to 90/100 (-5). Risk: LOW to LOW. 2 findings.

9590
Score
LOWLOW
Risk
ALLOW
Verdict

Findings

  • low command_injection: Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:__dirname, sanitizer:${JSON.stringify()
  • low no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: ruvnet