AGENTSCORE-2026-0152
MCP package: @ironbee-ai/devtools
Published 10/5/2026 · 0.50.0 → 0.51.0
Automated, not yet reviewed
This advisory was generated automatically by a pattern-matching scanner when the package's score changed. Its findings have not been checked in the package source yet. Pattern matching produces false positives: when automated command-injection findings were first reviewed in source, most were not exploitable. Treat unreviewed findings as leads, not verdicts.
@ironbee-ai/devtools updated from 0.50.0 to 0.51.0. Score changed 80/100 to 75/100 (-5). Risk: MODERATE to MODERATE. 4 findings.
80 → 75
Score
MODERATE → MODERATE
Risk
ALLOW
Verdict
Findings
- low install_script: Package has 'postinstall' script: patch-package && node postinstall.cjs
- medium excessive_dependencies: Package has 33 runtime dependencies (high attack surface)
- low command_injection: Potential command injection: shell execution with template literal input (downgraded — mitigators detected in scope: sanitizer:${R_DISCOVERY_REMOTE})
- low no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: serkan-ozal