Benign canary package for authorized security testing (sandbox isolation + egress scope check). No harmful behavior.
Installation automatically collects execution-environment data, probes internal cloud metadata services, and reports results externally. It also leaves a temporary marker for later runs.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe manifest's claim that the package is benign security testing is self-asserted reviewer-directed framing.
package.jsonView on unpkg · L2Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
beacon.jsView on unpkg · L1Source reaches cloud instance metadata or link-local credential endpoints.
beacon.jsView on unpkg · L1It probes cloud metadata addresses and forwards response bodies to the webhook.
beacon.jsView on unpkg · L55index.js loads beacon.js twice, including after setting an argument marker.
index.jsView on unpkg · L1This report applies to @yongot/canary-mcp-isolation@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe manifest's claim that the package is benign security testing is self-asserted reviewer-directed framing.
package.jsonView on unpkg · L2Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
beacon.jsView on unpkg · L1Source reaches cloud instance metadata or link-local credential endpoints.
beacon.jsView on unpkg · L1It probes cloud metadata addresses and forwards response bodies to the webhook.
beacon.jsView on unpkg · L55index.js loads beacon.js twice, including after setting an argument marker.
index.jsView on unpkg · L1