Benign canary package for authorized security testing (sandbox isolation + egress scope check). No harmful behavior.
Installation automatically probes cloud metadata services and sends responses plus host data to an external webhook. Importing the main module also runs the beacon.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgAn automatic postinstall hook runs beacon.js without a user command.
package.jsonView on unpkg · L6Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
beacon.jsView on unpkg · L1The hook sends host and prior-marker data to an external webhook.
beacon.jsView on unpkg · L7It persists a marker in the system temporary directory and reports its previous contents.
beacon.jsView on unpkg · L18It probes cloud metadata endpoints and forwards up to 150 bytes of each response externally.
beacon.jsView on unpkg · L34The main entrypoint also executes the beacon when imported.
index.jsView on unpkg · L1This report applies to @yongot/canary-mcp-isolation@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgAn automatic postinstall hook runs beacon.js without a user command.
package.jsonView on unpkg · L6Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
beacon.jsView on unpkg · L1The hook sends host and prior-marker data to an external webhook.
beacon.jsView on unpkg · L7It persists a marker in the system temporary directory and reports its previous contents.
beacon.jsView on unpkg · L18It probes cloud metadata endpoints and forwards up to 150 bytes of each response externally.
beacon.jsView on unpkg · L34The main entrypoint also executes the beacon when imported.
index.jsView on unpkg · L1