Skip to content

MCP and agent packages

The packages that advisories about the Model Context Protocol and AI agents name, with what the Exposure Registry knows about each one: the LLM components it declares and the authority its dependencies grant (shell, files, browser, network, code execution).

Advisories are grouped by topic. The Model Context Protocol view counts the records that match that topic, and the AI agents view counts those that match the AI agents or the agent-to-agent protocols topic. Package names are those the advisory source lists. How authority is measured

Advisories
339
Critical or high
240
Packages named
109
Advisories listed as exploited (CISA KEV)
2

140 advisories were published in the last 90 days and 81 in the 90 days before. 129 of the 339 name no package, because their source lists none.

Advisories by month of publication

May 2025: 22May 2025Jun 2025: 5Jul 2025: 6Aug 2025: 6Sep 2025: 12Oct 2025: 7Nov 2025: 3Dec 2025: 8Jan 2026: 10Jan 2026Feb 2026: 19Mar 2026: 29Apr 2026: 25May 2026: 39Jun 2026: 16Jul 2026: 43Aug 2026: 5050Sep 2026: 42Oct 2026: 1515Oct 2026
Advisories in this view, per month of publication
MonthItems
May 20252
Jun 20255
Jul 20256
Aug 20256
Sep 202512
Oct 20257
Nov 20253
Dec 20258
Jan 202610
Feb 202619
Mar 202629
Apr 202625
May 202639
Jun 202616
Jul 202643
Aug 202650
Sep 202642
Oct 202615

Authority in the registry

330 registry packages declare an MCP component or an agent framework. Their dependencies grant:

  • Outbound HTTP120Makes outbound requests, the precondition for server-side request forgery and exfiltration.
  • MCP tools90Exposes or calls Model Context Protocol tools, which pass authority between agents and servers.
  • File system24Reads or writes files, so path traversal and data exposure are in reach.
  • Browser control19Drives a browser, so it can act on websites with the user's sessions.
  • Code execution17Runs code it is given, so injected instructions can become arbitrary code.
  • Shell commands6Starts processes on the host, the most direct path from a prompt to the operating system.

All packages in the Exposure Registry

Advisories that name @anthropic-ai/claude-code

Close

npm. Every record that names the package, on any topic, newest first. RSS feed for this package

Packages named in advisories

109 packages

Packages named in advisories of this view, with their advisory count and registry entry
PackageAdvisoriesHighest severityLatest advisoryExploitedAuthority
@anthropic-ai/claude-codenpm22CriticalNot in the registry
n8nnpm10HighCode execution, File system, MCP tools, Shell commands
mcp-atlassianPyPI8CriticalNot in the registry
n8n-mcpnpm7CriticalNot in the registry
mcpPyPI6HighNone detected
fastmcpPyPI6CriticalNone detected
github.com/pinchtab/pinchtabGo6HighNot in the registry
github.com/hatchet-dev/hatchetGo5MediumNot in the registry
litellmPyPI5Critical2 on CISA KEVCode execution, Outbound HTTP, MCP tools
praisonaiPyPI4CriticalNot in the registry
pydantic-aiPyPI4HighNone detected
pydantic-ai-slimPyPI4HighOutbound HTTP
langflowPyPI4CriticalNone detected
omnigentPyPI4CriticalNot in the registry
mcp-searxngnpm4HighNot in the registry
flowisenpm4CriticalOutbound HTTP, MCP tools
flowise-componentsnpm4CriticalBrowser control, Code execution, Outbound HTTP, MCP tools
mcp-server-kubernetesnpm4HighNot in the registry
github.com/modelcontextprotocol/go-sdkGo4HighNone detected
@modelcontextprotocol/sdknpm3HighShell commands
rmcpcrates.io3HighOutbound HTTP
@aborruso/ckan-mcp-servernpm3MediumNot in the registry
github.com/sonirico/mcp-shellGo3HighNot in the registry
network-ainpm3CriticalNot in the registry
@evomap/evolvernpm3CriticalNot in the registry
github.com/pinchtab/pinchtab/cmd/pinchtabGo3HighNot in the registry
@ooples/token-optimizer-mcpnpm2HighNot in the registry
@bitbonsai/mcpvaultnpm2MediumNot in the registry
codewhale-tuicrates.io2HighNot in the registry
deepseek-tuicrates.io2HighNot in the registry
codewhalenpm2HighNot in the registry
deepseek-tuinpm2HighNot in the registry
chainlitPyPI2CriticalFile system, Outbound HTTP, MCP tools
@apify/actors-mcp-servernpm2HighNot in the registry
awslabs-aws-api-mcp-serverPyPI2HighNot in the registry
@agenticmail/corenpm2HighNot in the registry
@agenticmail/apinpm2HighNot in the registry
@grackle-ai/mcpnpm2HighNot in the registry
apm-cliPyPI2HighNot in the registry
@paperclipai/servernpm2CriticalNot in the registry
@openai/codexnpm2HighNot in the registry
@enclave-vm/corenpm2CriticalNot in the registry
agentsnpm2MediumNot in the registry
enclave-vmnpm2CriticalNot in the registry
opencode-ainpm2HighNot in the registry
neuron-core/neuron-aicomposer2CriticalNot in the registry
@modelcontextprotocol/clientnpm1HighShell commands
langflow-basePyPI1CriticalFile system, Outbound HTTP, MCP tools
lfxPyPI1CriticalFile system, Outbound HTTP, MCP tools
github.com/siyuan-note/siyuan/kernelGo1MediumNot in the registry

Topics are assigned by matching a record's title and summary against published patterns, so an advisory that never uses the words is missed and one that mentions them in passing is counted. An advisory that names several packages counts once for each. A package is listed with the ecosystem its advisory source states, and by name alone when the source states none.

Authority is read from the dependencies a package's latest release declares, and it is known only for packages the Exposure Registry tracks. It shows what a package's dependencies can do on the host. It does not show that a model is given that reach. Severity comes from the source advisory when it gives one, otherwise from the classifier. Dates are in UTC.