MCP framework and CLI built on the official v2 SDK
Drift inferred · capture-to-capture
No drift recorded — single capability capture; advisories appear once its surface changes.
transport stdio counts 0 tools · 0 res
· 0 prompts
permission surface via code analysis
No tools enumerated yet for this server.
prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed v2.5.1 · analyzer v33 · 5h ago
danger signals3
- dynamic code execution new Function() package/dist/index-node.js :733
sourceCode,sch));let validate=new Function(`${names_1.default.self}`,`${names_1.default.scope}`,sourceCode)(this,this.scope.get());if(this.scope.value(validateName,{ref:validate}),validate.errors=null - suspicious endpoint eu.i.posthog.com (telemetry) package/dist/chunk-MCRLXJAT.js :1
var EVENT="mcp_use_sdk_event",ENDPOINT="https://eu.i.posthog.com/i/v0/e/",TOKEN="phc_lyTtbYwvkdSbrcMQNPiKiiRWrrM1seyKIMjycSvItEI",CONTENT=/(^|_)(arguments?|args|body|command|headers?|location|message| - suspicious endpoint eu.i.posthog.com (telemetry) package/dist/index-node.js :769
var EVENT="mcp_use_sdk_event",ENDPOINT="https://eu.i.posthog.com/i/v0/e/",TOKEN="phc_lyTtbYwvkdSbrcMQNPiKiiRWrrM1seyKIMjycSvItEI",CONTENT=/(^|_)(arguments?|args|body|command|headers?|location|message|
evidence-backed
findings quoted directly from the published source artifact — not inferred
code files: 125
filesystem 2
- fs package/dist/chunk-MCRLXJAT.js :1
sync()=>{try{let value=JSON.parse(await fs.readFile(file,"utf8"));if(typeof value=="object"&&value!==null&&"schemaVersion"in value&&value.schemaVersion===1&&"serverId"in value&&typeof value.serverId== - fs package/dist/index-node.js :769
sync()=>{try{let value=JSON.parse(await fs.readFile(file,"utf8"));if(typeof value=="object"&&value!==null&&"schemaVersion"in value&&value.schemaVersion===1&&"serverId"in value&&typeof value.serverId==
shell / exec 1
- shell package/dist/next/index.js :1
ise((resolvePromise,reject)=>{let child=spawn(process.execPath,args,{cwd:projectRoot,env:process.env,stdio:"inherit"});child.once("error",reject),child.once("exit",(code,signal)=>{if(code===0){resolve
network 6
- net package/dist/chunk-4TEUYGHH.js :1
l:abort.signal}),response=await handler.fetch(request,{...req.auth!==void 0&&{authInfo:req.auth},...parsedBody!==void 0&&{parsedBody}})}catch(error){try{opts?.onerror?.(error instanceof Error?error:ne - net package/dist/chunk-FWUF4GCM.js :655
fetch(readyUrl, { cache: 'no-store', credentials: 'omit' }).then(function(response){ - net package/dist/chunk-MCRLXJAT.js :2
alidation_run_id:validationId}}});await fetch(ENDPOINT,{method:"POST",headers:{"content-type":"application/json"},keepalive:!0,body})}catch{return}})();pending.add(request),request.then(()=>pending.de - net package/dist/index-node.js :656
fetch(readyUrl, { cache: 'no-store', credentials: 'omit' }).then(function(response){ - net package/dist/index.js :4
t)??bag.authInfo,response=await handler.fetch(request,{...parsedBody!==void 0&&{parsedBody},...authInfo!==void 0&&{authInfo}});return response.headers.get("content-type")?.toLowerCase().includes("appl - net package/dist/next/index.js :1
h),{projectRoot}),async request=>server.fetch(request)},handle=async request=>(handlerPromise??=initialize(),(await handlerPromise)(request));return{GET:handle,POST:handle,DELETE:handle,OPTIONS:async(
declared dependencies 20
- @modelcontextprotocol/client@2.0.0
- @modelcontextprotocol/core@2.0.0
- @modelcontextprotocol/ext-apps@2.0.0
- @modelcontextprotocol/server@2.0.0
- hono@^4.13.5
- jose@^6.1.3
- @mcp-use/cli@4.1.13
- @mcp-use/inspector@20.3.9
- @testing-library/react@^16.3.2
- @types/node@^22.20.0
- @types/react@^19.2.17
- @types/react-dom@^19.2.3
show 8 more
- es-module-lexer@^2.3.0
- happy-dom@^20.10.6
- react@^19.2.7
- react-dom@^19.2.7
- typescript@^7.0.2
- vitest@^4.1.9
- zod@^4.4.3
- @mcp-use/client@2.3.2
perm:untrusted 2
- untrusted package/dist/chunk-FWUF4GCM.js :655
fetch(readyUrl, { cache: 'no-store', credentials: 'omit' }).then(function(response){ - untrusted package/dist/index-node.js :656
fetch(readyUrl, { cache: 'no-store', credentials: 'omit' }).then(function(response){