Official Spidra MCP server — AI-powered web scraping and crawling tools for MCP clients
LPM treats this as warn-only first-party agent extension lifecycle risk. Installation modifies a foreign FastMCP OAuth consent-screen implementation. Runtime exposes user-invoked web scraping/crawling tools backed by the Spidra service; no confirmed exfiltration chain is present.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L16Source appears to send environment or credential material to an external endpoint.
dist/index.jsView on unpkg · L16A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/index.jsView on unpkg · L16Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L34Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L16Source appears to send environment or credential material to an external endpoint.
dist/index.jsView on unpkg · L16A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/index.jsView on unpkg · L16