npm analyzed 1.4.1

@frontmcp/sdk

v1.4.1
npm

FrontMCP SDK

maintainer
davidfrontegg
license
Apache-2.0
first seen
2026-06-09
last seen
2026-06-17
releases · 30d
3
short id

Drift inferred · capture-to-capture

  1. HIGH code analysis flagged dynamic code execution ×3 in @frontmcp/sdk
capabilities 0 tools
transport streamable-http · sse counts 0 tools · 0 res · 0 prompts permission surface via code analysis

no tools enumerated yet for this server.

code evidence v1.4.1 · npm-tarball
evidence-backed findings quoted directly from the published source artifact — not inferred

declared dependencies 27

  • @frontmcp/auth@1.4.1
  • @frontmcp/di@1.4.1
  • @frontmcp/guard@1.4.1
  • @frontmcp/lazy-zod@1.4.1
  • @frontmcp/protocol@1.4.1
  • @frontmcp/uipack@1.4.1
  • @frontmcp/utils@1.4.1
  • @types/cors@^2.8.17
  • ioredis@^5.8.0
  • jose@^6.1.3
  • js-yaml@^4.1.1
  • reflect-metadata@^0.2.2
  • semver@^7.6.0
  • typescript@^5.9.3
  • @anthropic-ai/sdk@^0.30.0 || ^0.78.0
  • @enclave-vm/core@^2.13.0
  • @frontmcp/observability@1.4.1
  • @frontmcp/storage-sqlite@1.4.1
  • @opentelemetry/api@^1.9.0
  • @opentelemetry/sdk-trace-base@^1.25.0
  • @vercel/kv@^3.0.0
  • content-type@^1.0.5
  • cors@^2.8.5
  • express@^4.18.0 || ^5.0.0
  • openai@^4.0.0 || ^5.0.0 || ^6.0.0
  • raw-body@^3.0.0
  • vectoriadb@^2.2.0