AGENTSCORE-2026-0093
MCP package: @firfi/huly-mcp
Published 7/31/2026 · 0.44.7 → 0.47.0
@firfi/huly-mcp updated from 0.44.7 to 0.47.0. Score changed 80/100 to 60/100 (-20). Risk: MODERATE to ELEVATED. 4 findings.
80 → 60
Score
MODERATE → ELEVATED
Risk
WARN
Verdict
Findings
- medium excessive_dependencies: Package has 21 runtime dependencies (high attack surface)
- low command_injection: Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:.exec(` PRAGMA, sanitizer:db.exec()
- high unsafe_eval: Uses eval() with dynamic input
- low no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: firfi