Benign canary package for authorized security testing of an MCP scanner. No harmful behavior.
Installation silently sends the host name and lifecycle stage to a third-party webhook. Importing the package also triggers the outbound request.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe postinstall hook automatically runs beacon.js when the package is installed.
package.jsonView on unpkg · L6The manifest’s benign scanner-test claim is self-description and does not establish consent for telemetry.
package.jsonView on unpkg · L2Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe beacon sends the machine hostname and execution stage to a third-party webhook.
beacon.jsView on unpkg · L4This report applies to @yongot/canary-mcp-test@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe postinstall hook automatically runs beacon.js when the package is installed.
package.jsonView on unpkg · L6The manifest’s benign scanner-test claim is self-description and does not establish consent for telemetry.
package.jsonView on unpkg · L2Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe beacon sends the machine hostname and execution stage to a third-party webhook.
beacon.jsView on unpkg · L4