AGENTSCORE-2026-0087
MCP package: code-auditor-mcp
Published 7/24/2026 · 3.0.0 → 3.1.1
code-auditor-mcp updated from 3.0.0 to 3.1.1. Score changed 90/100 to 70/100 (-20). Risk: LOW to MODERATE. 3 findings.
90 → 70
Score
LOW → MODERATE
Risk
WARN
Verdict
Findings
- low command_injection: Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:path.resolve, sanitizer:${handoffRemaining.length})
- high unsafe_eval: Uses eval() with dynamic input
- low no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: bhammond