GetLib MCP - powerful modular self-hostable library docs MCP server and dashboard (Context7 alternative)
No confirmed malicious attack surface was established. The package runs an MCP server only when its declared command is invoked.
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/mcp.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/mcp.jsView on unpkg · L224Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/mcp.jsView on unpkg · L173A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/mcp.jsView on unpkg · L224A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
dist/mcp.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/mcp.jsView on unpkg · L187This report applies to getlib-mcp@1.1.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/mcp.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/mcp.jsView on unpkg · L224Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/mcp.jsView on unpkg · L173A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/mcp.jsView on unpkg · L224A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
dist/mcp.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/mcp.jsView on unpkg · L187