AGENTSCORE-2026-0159
MCP package: summer-engine
Published 10/7/2026 · 3.2.0 → 3.2.1
Automated, not yet reviewed
This advisory was generated automatically by a pattern-matching scanner when the package's score changed. Its findings have not been checked in the package source yet. Pattern matching produces false positives: when automated command-injection findings were first reviewed in source, most were not exploitable. Treat unreviewed findings as leads, not verdicts.
summer-engine updated from 3.2.0 to 3.2.1. Score changed 95/100 to 55/100 (-40). Risk: LOW to ELEVATED. 3 findings.
95 → 55
Score
LOW → ELEVATED
Risk
WARN
Verdict
Findings
- high command_injection: Potential command injection: shell execution with template literal input
- high unsafe_eval: Uses eval() with dynamic input
- low no_provenance: Package is not published with provenance attestations or trusted publishing. Published by: summer-engine