AgentScore is for sale. View the assets and acquisition details →
high

AGENTSCORE-2026-0073

MCP package: @meta-quest/hzdb

Published 6/30/2026 · 1.2.1 → 1.3.1

Withdrawn after review on 2026-09-24

The high-severity findings that triggered this advisory were checked in the package source and are not vulnerabilities. The reasons are listed under each finding below. The advisory stays at this address so the record is not silently rewritten. Reviewed in source: the flagged code was located in the published package, read in context and traced from input to sink (AI-assisted), and every confirmation was re-audited independently.

@meta-quest/hzdb updated from 1.2.1 to 1.3.1. Score changed 90/100 to 75/100 (-15). Risk: LOW to MODERATE. 2 findings.

90 → 75
Score
LOW → MODERATE
Risk
WARN
Verdict

Findings

  • high install_script: Package has 'postinstall' script: node -e "require('@meta-quest/metavr/postinstall.js')"Expected behaviourThe install script downloads the vendor's own native CLI against a pinned digest. Expected behaviour for this package, not a vulnerability.
  • low no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: zbowling