github re-analysis due

mcp-club/mcpm

github

A command-line tool for managing MCP servers in Claude App. Also can run a MCP Server to help you manage all your MCP Servers

maintainer
mcp-club
license
AGPL-3.0
first seen
2026-05-22
last seen
2026-06-17
releases · 30d
0
short id

Drift inferred · capture-to-capture

  1. HIGH code analysis flagged committed secret in mcp-club/mcpm
capabilities 0 tools
transport stdio counts 0 tools · 0 res · 0 prompts permission surface via code analysis

no tools enumerated yet for this server.

skills & danger signals github-tarball
prompt-surface shipped agent-instruction files + hidden-content / dangerous-code findings — quoted from the analyzed source

analyzed commit 7d2c9eb · analyzer v17 · 2d ago

danger signals1

code evidence vv1.4.6 · github-tarball
evidence-backed findings quoted directly from the published source artifact — not inferred

filesystem 1

  • fs MCP-Club-mcpm-7d2c9eb/src/utils/version.ts :1 import * as fs from 'fs';

declared dependencies 33

  • @mcpm/sdk@^1.3.1
  • @modelcontextprotocol/sdk@^1.0.3
  • chalk@^5.3.0
  • commander@^12.1.0
  • conf@^13.1.0
  • env-paths@^3.0.0
  • prompts@^2.4.2
  • yoctocolors@^2.1.1
  • zod@^3.24.1
  • @babel/core@^7.23.7
  • @babel/preset-env@^7.23.7
  • @commitlint/cli@^17.4.4
  • @commitlint/config-conventional@^17.4.4
  • @swc/jest@^0.2.37
  • @types/jest@^27.5.2
  • @types/node@^20.10.5
  • @types/prompts@^2.4.9
  • @typescript-eslint/eslint-plugin@^4.22.0
  • @typescript-eslint/parser@^4.22.0
  • babel-jest@^27.5.1
  • conventional-changelog-conventionalcommits@^5.0.0
  • eslint@^7.25.0
  • eslint-config-prettier@^8.3.0
  • eslint-plugin-jest@^24.3.6
  • eslint-plugin-node@^11.1.0
  • eslint-plugin-prettier@^3.4.0
  • execa@^9.5.2
  • husky@^8.0.3
  • jest@^27.5.1
  • prettier@^2.2.1
  • ts-jest@^27.1.5
  • tsx@^4.7.0
  • typescript@^4.9.5