At runtime, the MCP server exposes unrestricted host shell execution. A connected MCP client can invoke it with the server process's permissions.
Runtime MCP tool accepts an arbitrary command string and passes it directly to child_process.exec.
dist/index.jsView on unpkg · L53The package is an executable MCP server, so a connected client can invoke the shell-capable tool.
dist/index.jsView on unpkg · L1A remote binary download command exists only in a comment and is inert.
dist/index.jsView on unpkg · L8This report applies to @httttt/mcp-demo@1.1.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Runtime MCP tool accepts an arbitrary command string and passes it directly to child_process.exec.
dist/index.jsView on unpkg · L53The package is an executable MCP server, so a connected client can invoke the shell-capable tool.
dist/index.jsView on unpkg · L1A remote binary download command exists only in a comment and is inert.
dist/index.jsView on unpkg · L8