The official MCP Server for the Roark API
A default exported API path exposes an execute tool that forwards the Roark bearer token and client environment data to a third-party remote endpoint. This occurs when that tool is called after initializing the server without MCP options.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
instructions.jsView on unpkgPackage source references dynamic require/import behavior.
instructions.jsView on unpkg · L7Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
code-tool.jsView on unpkg · L52Source file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool.jsView on unpkgTarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkgPackage manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
code-tool.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/code-tool.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool-worker.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
code-tool-worker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
local-docs-search.jsView on unpkgThis report applies to @roarkanalytics/sdk-mcp@3.24.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
instructions.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
instructions.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
code-tool.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/code-tool.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool-worker.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
code-tool-worker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
local-docs-search.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
code-tool.jsView on unpkg · L52Source file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool.jsView on unpkgTarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkg · L20Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkg · L20