AgentScore is for sale. View the assets and acquisition details →
high

AGENTSCORE-2026-0071

MCP package: slashvibe-mcp

Published 6/27/2026 · 0.4.10 → 0.5.0

Confirmed by review on 2026-09-25

At least one finding below was checked in the package source and is a real vulnerability. Details and fixed versions are listed under the finding. Reviewed in source: the flagged code was located in the published package, read in context and traced from input to sink (AI-assisted), and every confirmation was re-audited independently.

slashvibe-mcp updated from 0.4.10 to 0.5.0. Score changed 90/100 to 65/100 (-25). Risk: LOW to ELEVATED. 3 findings.

90 → 65
Score
LOW → ELEVATED
Risk
WARN
Verdict

Findings

  • medium hardcoded_secret: Hardcoded secret found (AWS key, OpenAI key, GitHub token, or npm token) (downgraded — mitigators detected in scope: test_fixture:// TEST, test_fixture:abcdef)
  • high command_injection: Potential command injection: shell execution with template literal inputConfirmedOn macOS, text from other users of the service (messages, presence notes, posts) reaches a shell command through desktop notifications. Affects 0.2.0 to 0.5.6; fixed in 0.5.7.
  • low no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: brightseth