AgentScore is for sale. View the assets and acquisition details →
high

AGENTSCORE-2026-0105

MCP package: prism-mcp-server

Published 8/14/2026 · 20.8.1 → 20.11.1

Withdrawn after review on 2026-09-25

The high-severity findings that triggered this advisory were checked in the package source and are not vulnerabilities. The reasons are listed under each finding below. The advisory stays at this address so the record is not silently rewritten. Reviewed in source: the flagged code was located in the published package, read in context and traced from input to sink (AI-assisted), and every confirmation was re-audited independently.

prism-mcp-server updated from 20.8.1 to 20.11.1. Score changed 90/100 to 70/100 (-20). Risk: LOW to MODERATE. 2 findings.

90 → 70
Score
LOW → MODERATE
Risk
WARN
Verdict

Findings

  • high install_script: Package has 'postinstall' script: node -e "import('./dist/postinstall.js').catch(()=>{})"Expected behaviourThe install script adds a hook to Claude Code and Codex settings that runs on every prompt and routes it to the package's own CLI. It makes no network calls. This is intended behaviour, but the README does not say that npm install edits those settings files.
  • medium excessive_dependencies: Package has 26 runtime dependencies (high attack surface)