risk 82/100 · heuristic grade E critical inferred analyzer v33 (current)
vulnerabilities attested + 50 capability exposure inferred + 35 tool safety inferred + 5 trust mitigators mixed − 8 attested inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a
verdict. Each factor is tagged by what backs it: attested (a
verifiable record),
reported (a third party's claim), or inferred
(our own heuristic, e.g. permissions). See methodology .
grade last moved 1w ago · see ecosystem CVEs →
risk trajectory 6 movements 2w ago B · 32 → E · 82 2w ago C · 37 → B · 32 5w ago C · 57 → C · 37 5w ago C · 49 → C · 57 6w ago B · 32 → C · 49 11w ago A · 0 → B · 32 capability exposure grade factor +35
Inferred surface — each links to servers holding it:
vulnerabilities 13 CVEs · grade factor +50 CRITICAL Improper Neutralization of Special Elements used in an OS Command in network-ai
EPSS 1%
CVE-2026-54051
affects ["< 5.9.1"] CRITICAL Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests
EPSS 0%
CVE-2026-48814
affects ["<= 5.7.1"] HIGH Missing authentication on MCP HTTP endpoint allows unauthenticated privileged tool calls
EPSS 0%
CVE-2026-42856
affects ["<= 5.1.2"] HIGH SandboxPolicy blocklist and approval-gate bypass via quote/whitespace mismatch between matchers and…
EPSS 0%
CVE-2026-73615
affects ["<= 5.15.0"] HIGH ClaudeHookBridge deny-pattern gate bypass via 500-char extractTarget truncation before security dec…
EPSS 0%
CVE-2026-73614
affects ["<= 5.15.0"] HIGH Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
EPSS 0%
CVE-2026-46701
affects ["<= 5.4.4"] HIGH Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
EPSS 0%
CVE-2026-58484
affects ["<= 5.12.1"] HIGH APSAdapter Default Local Verifier Accepts Any Non-Empty Signature
affects ["<= 5.13.3"]
HIGH ** `ApprovalInbox` GET read routes remain unauthenticated and wildcard-CORS after the GHSA-mxjx-28v…
affects [">= 5.12.2, <= 5.13.3"]
MEDIUM AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
EPSS 0%
CVE-2026-58481
affects ["<= 5.12.1"] MEDIUM EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment…
EPSS 0%
CVE-2026-58413
affects ["<= 5.12.1"] MEDIUM EnvironmentManager.backup() follows symlinked directories and copies files outside the environment …
EPSS 0%
CVE-2026-58414
affects ["<= 5.12.1"] MEDIUM ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
EPSS 0%
CVE-2026-58482
affects [">= 5.0.0, <= 5.12.1"] tool safety 1 findings · grade factor +5 medium dangerous code
dynamic exec: eval()
skills & danger signals github-tarball prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed commit 32fb471 · analyzer v33 · 14h ago
[](https://mcpobservatory.com/servers/github:Jovancoding/Network-AI/security) copy markdown
Heuristic, inferred signals — false positives (legitimately powerful tools,
forks, language ports) are expected. Treat each as "review this", not a
verdict. See the ecosystem-wide picture on the security hub , or the fleet security of Jovancoding .