Drift inferred · capture-to-capture
No drift recorded — single capability capture; advisories appear once its surface changes.
transport stdio · http · sse counts 0 tools · 0 res
· 0 prompts
permission surface via code analysis
no tools enumerated yet for this server.
prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed commit 34b696d · analyzer v18 · 9h ago
danger signals1
- credential in logscredential in logHenryHaoson-Yuque-MCP-Server-34b696d/src/server.ts:271
Logger.log(`accessToken: ${accessToken}`);
evidence-backed
findings quoted directly from the published source artifact — not inferred
network 2
- net HenryHaoson-Yuque-MCP-Server-34b696d/src/server.ts :6
import { IncomingMessage, ServerResponse } from "http"; - net HenryHaoson-Yuque-MCP-Server-34b696d/src/services/yuque.ts :1
import axios, { AxiosInstance } from 'axios';
secrets 1
- secrets HenryHaoson-Yuque-MCP-Server-34b696d/src/config.ts :18
yuqueApiToken: process.env.YUQUE_API_TOKEN,
declared dependencies 16
- @modelcontextprotocol/sdk@^1.6.1
- @types/content-type@^1.1.8
- axios@^1.8.1
- content-type@^1.0.5
- cors@^2.8.5
- cross-env@^7.0.3
- dotenv@^16.4.7
- express@^4.21.2
- raw-body@^3.0.0
- zod@^3.24.2
- @types/express@^5.0.0
- @types/node@^22.13.9
- nodemon@^3.1.9
- ts-node@^10.9.2
- ts-node-dev@^2.0.0
- typescript@^5.8.2