AGENTSCORE-2026-0141
MCP package: @sentry/mcp-server
Published 9/30/2026 · 0.40.0 → 0.42.0
Automated, not yet reviewed
This advisory was generated automatically by a pattern-matching scanner when the package's score changed. Its findings have not been checked in the package source yet. Pattern matching produces false positives: when automated command-injection findings were first reviewed in source, most were not exploitable. Treat unreviewed findings as leads, not verdicts.
@sentry/mcp-server updated from 0.40.0 to 0.42.0. Score changed 85/100 to 70/100 (-15). Risk: LOW to MODERATE. 3 findings.
85 → 70
Score
LOW → MODERATE
Risk
WARN
Verdict
Findings
- low poor_description: Package has no meaningful description
- high command_injection: Potential command injection: shell execution with template literal input
- low no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: sentry-bot