AgentScore is for sale. View the assets and acquisition details →
high

AGENTSCORE-2026-0108

MCP package: browse-ai

Published 8/24/2026 · 0.3.2 → 1.0.0

Withdrawn after review on 2026-09-25

The high-severity findings that triggered this advisory were checked in the package source and are not vulnerabilities. The reasons are listed under each finding below. The advisory stays at this address so the record is not silently rewritten. Reviewed in source: the flagged code was located in the published package, read in context and traced from input to sink (AI-assisted), and every confirmation was re-audited independently.

browse-ai updated from 0.3.2 to 1.0.0. Score changed 95/100 to 60/100 (-35). Risk: LOW to ELEVATED. 4 findings.

95 → 60
Score
LOW → ELEVATED
Risk
WARN
Verdict

Findings

  • high install_script: Package has 'postinstall' script: node -e "console.warn(' ⚠ browse-ai is now lastsearch — https://lastsearch.ai/migrate (this bridge stops working 2026-10-31) ')"Not a vulnerabilityThe postinstall script only prints a rename notice.
  • medium no_repository: Package has no repository link — source code is not verifiable
  • low no_license: Package has no licence specified
  • low no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: shreyassaw