MCP server for the Warp freight API, covering the full booking lifecycle: mode compare (one call prices every eligible mode in parallel and returns a decision-complete recommendation with the cost-vs-transit math), quote (van/box-truck/FTL/LTL — LTL split
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically modifies Claude Desktop's MCP configuration. The resulting entry launches the package with the user's home-directory access.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgManifest entrypoint contains risky behavior absent from dist/build output.
scripts/run.mjsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/run.mjsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.mjsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/client.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/check-description.mjsView on unpkgThis report applies to warp-agent-mcp@0.19.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L36Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L36A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/client.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/check-description.mjsView on unpkgManifest entrypoint contains risky behavior absent from dist/build output.
scripts/run.mjsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/run.mjsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.mjsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.mjsView on unpkg