npm JavaScript analyzed 2.0.0

@modelcontextprotocol/client

v2.0.0
npm

Model Context Protocol implementation for TypeScript - Client package

maintainer
ashwin-ant
license
MIT
first seen
2026-06-09
last seen
2026-08-02
releases · 30d
4
short id

Drift inferred · capture-to-capture

  1. HIGH code analysis flagged dynamic code execution ×2 in @modelcontextprotocol/client
  2. HIGH code analysis flagged dynamic code execution ×2 in @modelcontextprotocol/client
  3. HIGH code analysis flagged dynamic code execution ×2 in @modelcontextprotocol/client
  4. HIGH code analysis flagged dynamic code execution in @modelcontextprotocol/client
  5. HIGH code analysis flagged dynamic code execution in @modelcontextprotocol/client
  6. HIGH code analysis flagged dynamic code execution in @modelcontextprotocol/client
  7. HIGH code analysis flagged dynamic code execution in @modelcontextprotocol/client
capabilities 2 tools
transport counts 2 tools · 0 res · 0 prompts permission surface via code analysis

tools

  • deploy
  • greet
skills & danger signals npm-tarball
prompt-surface shipped agent-instruction files + hidden-content / dangerous-code findings — quoted from the analyzed source

analyzed v2.0.0 · analyzer v28 · 3d ago

danger signals2

code evidence v2.0.0 · npm-tarball
evidence-backed findings quoted directly from the published source artifact — not inferred

code files: 24

shell / exec 1

  • shell package/dist/stdio.mjs :68 this._process = spawn(this._serverParams.command, this._serverParams.args ?? [], {

network 8

  • net package/dist/index.cjs :925 * However, `fetch()` also throws `TypeError` for non-CORS failures (DNS resolution, connection
  • net package/dist/index.mjs :922 * However, `fetch()` also throws `TypeError` for non-CORS failures (DNS resolution, connection
  • net package/dist/shimsBrowser.cjs :5 * Whether `fetch()` may throw `TypeError` due to CORS. Only true in browser contexts
  • net package/dist/shimsBrowser.mjs :5 * Whether `fetch()` may throw `TypeError` due to CORS. Only true in browser contexts
  • net package/dist/shimsNode.cjs :5 * Whether `fetch()` may throw `TypeError` due to CORS. CORS is a browser-only concept —
  • net package/dist/shimsNode.mjs :5 * Whether `fetch()` may throw `TypeError` due to CORS. CORS is a browser-only concept —
  • net package/dist/shimsWorkerd.cjs :12 * Whether `fetch()` may throw `TypeError` due to CORS. CORS is a browser-only concept —
  • net package/dist/shimsWorkerd.mjs :12 * Whether `fetch()` may throw `TypeError` due to CORS. CORS is a browser-only concept —

tool registrations 4

  • deploy package/dist/src-D_zzAWoS.mjs :4948
  • greet package/dist/src-D_zzAWoS.mjs :7042
  • deploy package/dist/src-NAgB4Mp8.cjs :4949
  • greet package/dist/src-NAgB4Mp8.cjs :7051

declared dependencies 28

  • @modelcontextprotocol/core@2.0.0
  • @modelcontextprotocol/core-internal@^2.0.0
  • @modelcontextprotocol/tsconfig@^2.0.0
  • @modelcontextprotocol/eslint-config@^2.0.0
  • @modelcontextprotocol/vitest-config@^2.0.0
  • @modelcontextprotocol/test-helpers@^2.0.0
  • cross-spawn@^7.0.5
  • eventsource@^3.0.2
  • eventsource-parser@^3.0.0
  • jose@^6.1.3
  • pkce-challenge@^5.0.0
  • zod@^4.2.0
  • @cfworker/json-schema@^4.1.1
  • ajv@^8.17.1
  • ajv-formats@^3.0.1
  • @types/content-type@^1.1.8
  • @types/cross-spawn@^6.0.6
  • @types/eventsource@^1.1.15
  • @typescript/native-preview@^7.0.0-dev.20251217.1
  • @eslint/js@^9.39.2
  • eslint@^9.39.2
  • eslint-config-prettier@^10.1.8
  • eslint-plugin-n@^17.23.1
  • prettier@3.6.2
  • typescript@^5.9.3
  • typescript-eslint@^8.48.1
  • vitest@^4.0.15
  • tsdown@^0.18.0