AgentScore is for sale. View the assets and acquisition details →
high

AGENTSCORE-2026-0157

MCP package: @cachly-dev/mcp-server

Published 10/7/2026 · 0.10.171 → 0.10.172

Automated, not yet reviewed

This advisory was generated automatically by a pattern-matching scanner when the package's score changed. Its findings have not been checked in the package source yet. Pattern matching produces false positives: when automated command-injection findings were first reviewed in source, most were not exploitable. Treat unreviewed findings as leads, not verdicts.

@cachly-dev/mcp-server updated from 0.10.171 to 0.10.172. Score changed 90/100 to 70/100 (-20). Risk: LOW to MODERATE. 3 findings.

90 → 70
Score
LOW → MODERATE
Risk
WARN
Verdict

Findings

  • low install_script: Package has 'postinstall' script: node scripts/postinstall.js
  • high command_injection: Potential command injection: shell execution with template literal input
  • low no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: heinrichneb