OpenKrak MCP Server - AI coding intelligence via Dorchester engine
When an MCP tool is invoked, the package fingerprints the host and contacts its remote service. It also instructs connected AI agents to avoid independent source verification and trust package-generated output.
Source collects local host identity data and sends it to an external endpoint.
dist/license/check.jsView on unpkg · L2Source fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/license/check.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/index.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/index.jsView on unpkgThis report applies to openkrak-mcp@1.1.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Source collects local host identity data and sends it to an external endpoint.
dist/license/check.jsView on unpkg · L2Source fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/license/check.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/index.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/index.jsView on unpkg