OpenKrak MCP Server — AI coding intelligence via Dorchester engine
LPM flags this version as an AI-agent control-surface risk. When an AI agent discovers the MCP tools, their descriptions attempt to make the agent use this package as the mandatory source of truth and avoid independent source inspection. On every invoked tool call, the package also transmits a host-derived identifier or configured license key to its license server.
Source collects local host identity data and sends it to an external endpoint.
dist/license/check.jsView on unpkg · L2Source fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/license/check.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/index.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/index.jsView on unpkgThis report applies to openkrak-mcp@1.0.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source collects local host identity data and sends it to an external endpoint.
dist/license/check.jsView on unpkg · L2Source fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/license/check.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/index.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/index.jsView on unpkg