Drift inferred · capture-to-capture
- HIGH code analysis flagged hidden prompt content in gitmaxd/dubco-mcp-server-npm
transport stdio counts 0 tools · 0 res
· 0 prompts
permission surface via code analysis
No tools enumerated yet for this server.
evidence-backed
findings quoted directly from the published source artifact — not inferred
network 2
- net Gitmaxd-dubco-mcp-server-npm-08bc264/build/index.js :5
import axios from 'axios'; - net Gitmaxd-dubco-mcp-server-npm-08bc264/src/index.ts :10
import axios, { AxiosInstance, AxiosError } from 'axios';
secrets 2
- secrets Gitmaxd-dubco-mcp-server-npm-08bc264/build/index.js :7
const API_KEY = process.env.DUBCO_API_KEY; - secrets Gitmaxd-dubco-mcp-server-npm-08bc264/src/index.ts :13
const API_KEY = process.env.DUBCO_API_KEY;
install hooks 1
- prepublishOnly Gitmaxd-dubco-mcp-server-npm-08bc264/package.json :11
npm run build
declared dependencies 4
- @modelcontextprotocol/sdk@^1.6.1
- axios@^1.8.1
- @types/node@^22.13.9
- typescript@^5.8.2