A Model Context Protocol (MCP) server for accessing Computrabajo job listings in Latin America
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically modifies the global Claude skills directory. An explicit remote-login command also transmits a browser session cookie to the configured remote server, which defaults to a maintainer worker.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource appears to send environment or credential material to an external endpoint.
dist/src/index.jsView on unpkg · L144A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/src/index.jsView on unpkg · L144A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/src/index.jsView on unpkg · L144Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-skills.mjsView on unpkg · L7This report applies to mcp-computrabajo-open@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L51Source appears to send environment or credential material to an external endpoint.
dist/src/index.jsView on unpkg · L144A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/src/index.jsView on unpkg · L144A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/src/index.jsView on unpkg · L144Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-skills.mjsView on unpkg · L7