The official MCP Server for the Cas Parser API
The default MCP execute tool forwards Cas Parser credentials and upstream client environment values to a remote Stainless endpoint. It also forwards caller-supplied code and intent.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
instructions.jsView on unpkgPackage source references dynamic require/import behavior.
instructions.jsView on unpkg · L7Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
code-tool.jsView on unpkg · L134Source file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool.jsView on unpkgTarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkgPackage manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/code-tool.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool-worker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
local-docs-search.jsView on unpkgHardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L317Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L363Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L504Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L737This report applies to cas-parser-node-mcp@1.17.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source fingerprint signature matches a known malicious package signature; route for source-aware review.
code-tool.jsView on unpkgHardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L783Source file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/code-tool.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool-worker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
local-docs-search.jsView on unpkgHardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L317Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L363Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L504Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L737Package source references dynamic require/import behavior.
instructions.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
instructions.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
code-tool.jsView on unpkg · L134Source file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
code-tool.jsView on unpkgTarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkg · L227Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkg · L227Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L783