The official MCP Server for the Plumery API
The default MCP execute capability sends code and runtime authentication-related data to a third-party remote execution endpoint. This creates a concrete credential and data disclosure path whenever the tool is used.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
instructions.jsView on unpkgPackage source references dynamic require/import behavior.
instructions.jsView on unpkg · L7Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
code-tool.jsView on unpkg · L134Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkgPackage manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool-worker.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
code-tool-worker.jsView on unpkgHardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L7141Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L7146Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L7151Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L9411This report applies to plumery-mcp@3.9.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L9416Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L9421Source file is highly similar to a previously finalized malicious package; route for source-aware review.
code-tool-worker.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
code-tool-worker.jsView on unpkgHardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L7141Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L7146Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L7151Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L9411Package source references dynamic require/import behavior.
instructions.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
instructions.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
code-tool.jsView on unpkg · L134Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkg · L21Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkg · L21Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L9416Hardcoded password in src/local-docs-search.ts
src/local-docs-search.tsView on unpkg · L9421