retry queued — source fetch failed — will retry
TypeScript AI SDK with 24+ LLM providers behind one consistent API. MCP-native (connect any MCP server), voice TTS/STT/realtime, RAG, agents, memory, context compaction. OpenAI · Anthropic · Gemini · Bedrock · Azure · Ollama · DeepSeek · NVIDIA NIM and mo
Insufficient evidence to grade. This server's source has not been statically analyzed, so a low grade would only mean "nothing found", not "nothing there". We don't show a reassuring grade we can't stand behind. Attested signals (CVEs, provenance) below still apply.
Once the source is analyzed (see the analysis flag in the header), a graded score appears here. How analysis works: methodology.
- C · 45 → B · 33
- C · 53 → C · 45
- D · 68 → C · 53
- D · 70 → D · 68
- D · 62 → D · 70
- D · 72 → D · 62
No known CVEs for this server.
- high dangerous code
committed secret: Anthropic key · dynamic exec: new Function() · obfuscated payload: dynamic require()/import()
- medium dangerous code
env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- medium dangerous code
env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- medium dangerous code
env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
- medium dangerous code
env-secret-flows-to-network-js: A process environment value reaches a network call. Review whether it is a credential leaving the process; the ordinary API-wrapper shape (read a ke
analyzed v12.14.16 · analyzer v33 · 18m ago
danger signals9
- dynamic code execution new Function() package/dist/agent/directTools.js :287
const result = new Function(`'use strict'; return (${expression})`)(); - dynamic code execution new Function() package/dist/utils/schemaConversion.js :634
const createZodSchema = new Function("z", `return ${schemaExpression}`); - suspicious endpoint app.posthog.com (telemetry) package/dist/cli/commands/telemetry.js :683
POSTHOG_HOST: "https://app.posthog.com (optional)", - suspicious endpoint api.datadoghq.com (telemetry) package/dist/observability/exporters/datadogExporter.js :36
? "https://api.datadoghq.com/api/v1/validate" - suspicious endpoint app.posthog.com (telemetry) package/dist/observability/exporters/posthogExporter.js :20
this.host = config.host ?? "https://app.posthog.com"; - over-broad OAuth scope https://www.googleapis.com/auth/cloud-platform
expected for this server's purpose
package/dist/adapters/video/vertexVideoHandler.js :160
scopes: ["https://www.googleapis.com/auth/cloud-platform"], - over-broad OAuth scope https://www.googleapis.com/auth/cloud-platform
expected for this server's purpose
package/dist/providers/googleVertex/client.js :5935
scopes: ["https://www.googleapis.com/auth/cloud-platform"], - over-broad OAuth scope https://www.googleapis.com/auth/cloud-platform
expected for this server's purpose
package/dist/voice/providers/GoogleSTT.js :432
scopes: ["https://www.googleapis.com/auth/cloud-platform"], - committed secret Anthropic key package/dist/utils/providerSetupMessages.js :23
sk-ant…(31 chars, redacted)
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of balaganesh_juspay.