The official MCP Server for the Nimble API
At MCP runtime, the default execute tool forwards the Nimble credential and submitted code to a Stainless-hosted endpoint. Local execution evaluates caller-supplied code in a constrained Deno worker.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
instructions.jsView on unpkgPackage source references dynamic require/import behavior.
instructions.jsView on unpkg · L7Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
code-tool.mjsView on unpkg · L12Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkgPackage manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool-worker.jsView on unpkgThis report applies to nimble-js-mcp@1.4.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
instructions.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
instructions.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool-worker.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
code-tool.mjsView on unpkg · L12Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkg · L227Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkg · L227