The official MCP Server for the Nimble API
Static analysis flagged 9 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package source references dynamic require/import behavior.
instructions.jsView on unpkg · L7Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkgPackage manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgThis report applies to nimble-js-mcp@0.19.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
instructions.jsView on unpkg · L7Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkg · L227Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkg · L227