AgentScore is for sale. View the assets and acquisition details →
high

AGENTSCORE-2026-0135

MCP package: @yun520-1/heartflow

Published 9/28/2026 · 6.7.77 → 6.7.124

Automated, not yet reviewed

This advisory was generated automatically by a pattern-matching scanner when the package's score changed. Its findings have not been checked in the package source yet. Pattern matching produces false positives: when automated command-injection findings were first reviewed in source, most were not exploitable. Treat unreviewed findings as leads, not verdicts.

@yun520-1/heartflow updated from 6.7.77 to 6.7.124. Score changed 85/100 to 55/100 (-30). Risk: LOW to ELEVATED. 3 findings.

85 → 55
Score
LOW → ELEVATED
Risk
WARN
Verdict

Findings

  • high command_injection: Potential command injection: shell execution with template literal input
  • high unsafe_eval: Uses eval() with dynamic input
  • low no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: yun520-1