Loading npm security reports…
ScoreHub local MCP proxy — OAuth login, token caching, and tool forwarding to remote MCP endpoint
OAuth token exchanges accept invalid TLS certificates. This can expose OAuth credentials during authorization or refresh under a network MITM.
dist/auth.js disables TLS certificate verification for OAuth token POSTs.
dist/auth.jsView on unpkgAn active network attacker could intercept authorization-code or refresh-token exchanges.
package.jsonView on unpkgdist/auth.js disables TLS certificate verification for OAuth token POSTs.
dist/auth.jsView on unpkgAn active network attacker could intercept authorization-code or refresh-token exchanges.
package.jsonView on unpkg · L20