Use with caution. Address findings before production.
Scanned 5/7/2026, 5:37:32 AM·Cached result·Deep Scan·88 rules·How we decide ↗
AIVSS Score
Medium
Severity Breakdown
0
critical
2
high
4
medium
0
low
MCP Server Information
Findings
This package carries a C grade with a safety score of 73/100 due to two high-severity issues and four medium-severity issues, primarily centered on prompt injection vulnerabilities (3 instances) and insecure server configuration (2 instances). The prompt injection risks are the most concerning as they could allow attackers to manipulate the package's behavior through crafted inputs, while the configuration issues and one insecure container image reference add additional attack surface. You should address these vulnerabilities before deployment, particularly the prompt injection flaws, or consider alternative packages with stronger security postures.
AIPer-finding remediation generated by bedrock-claude-haiku-4-5 — 6 of 6 findings. Click any finding to read.
Scan Details
Done
Sign in to save scan history and re-scan automatically on new commits.
Building your own MCP server?
Same rules, same LLM judges, same grade. Private scans stay isolated to your account and never appear in the public registry. Required for code your team hasn’t shipped yet.
6 of 6 findings
6 findings