Skip to content

MCP and agent packages

The packages that advisories about the Model Context Protocol and AI agents name, with what the Exposure Registry knows about each one: the LLM components it declares and the authority its dependencies grant (shell, files, browser, network, code execution).

Advisories are grouped by topic. The Model Context Protocol view counts the records that match that topic, and the AI agents view counts those that match the AI agents or the agent-to-agent protocols topic. Package names are those the advisory source lists. How authority is measured

Advisories
339
Critical or high
240
Packages named
109
Advisories listed as exploited (CISA KEV)
2

140 advisories were published in the last 90 days and 81 in the 90 days before. 129 of the 339 name no package, because their source lists none.

Advisories by month of publication

May 2025: 22May 2025Jun 2025: 5Jul 2025: 6Aug 2025: 6Sep 2025: 12Oct 2025: 7Nov 2025: 3Dec 2025: 8Jan 2026: 10Jan 2026Feb 2026: 19Mar 2026: 29Apr 2026: 25May 2026: 39Jun 2026: 16Jul 2026: 43Aug 2026: 5050Sep 2026: 42Oct 2026: 1515Oct 2026
Advisories in this view, per month of publication
MonthItems
May 20252
Jun 20255
Jul 20256
Aug 20256
Sep 202512
Oct 20257
Nov 20253
Dec 20258
Jan 202610
Feb 202619
Mar 202629
Apr 202625
May 202639
Jun 202616
Jul 202643
Aug 202650
Sep 202642
Oct 202615

Authority in the registry

330 registry packages declare an MCP component or an agent framework. Their dependencies grant:

  • Outbound HTTP120Makes outbound requests, the precondition for server-side request forgery and exfiltration.
  • MCP tools90Exposes or calls Model Context Protocol tools, which pass authority between agents and servers.
  • File system24Reads or writes files, so path traversal and data exposure are in reach.
  • Browser control19Drives a browser, so it can act on websites with the user's sessions.
  • Code execution17Runs code it is given, so injected instructions can become arbitrary code.
  • Shell commands6Starts processes on the host, the most direct path from a prompt to the operating system.

All packages in the Exposure Registry

Advisories that name @contentful/mcp-server

Close

npm. Every record that names the package, on any topic, newest first. RSS feed for this package

Packages named in advisories

109 packages

Packages named in advisories of this view, with their advisory count and registry entry
PackageAdvisoriesHighest severityLatest advisoryExploitedAuthority
clinenpm1HighNot in the registry
@bytebase/dbhubnpm1CriticalNot in the registry
@roomi-fields/notebooklm-mcpnpm1HighNot in the registry
hatchetGo1HighNot in the registry
hatchet-dev/hatchetGo1MediumNot in the registry
github.com/stacklok/toolhiveGo1HighNot in the registry
@andrea9293/mcp-documentation-servernpm1HighNot in the registry
functype-mcp-servernpm1HighNot in the registry
browse-mcpnpm1HighNot in the registry
nextcloud-mcp-serverPyPI1CriticalNot in the registry
@contentful/mcp-servernpm1HighNot in the registry
@contentful/mcp-toolsnpm1HighNot in the registry
claude-faf-mcpnpm1HighNot in the registry
faf-mcpnpm1HighNot in the registry
grok-faf-mcpnpm1HighNot in the registry
atomic-agents-stackPyPI1HighNot in the registry
neuro-cortex-memoryPyPI1HighNot in the registry
@trigger.dev/corenpm1HighNot in the registry
@jshookmcp/jshooknpm1MediumNot in the registry
stata-mcpPyPI1HighNot in the registry
gemini-bridgePyPI1MediumNot in the registry
n8nEcosystem not stated1HighNot in the registry
@agenticmail/claudecodenpm1HighNot in the registry
@agenticmail/codexnpm1HighNot in the registry
@agenticmail/openclawnpm1HighNot in the registry
mcp-memory-keepernpm1MediumNot in the registry
langbotPyPI1HighNot in the registry
phantom-audioPyPI1HighNot in the registry
github.com/coder/coder/v2Go1MediumNot in the registry
@grackle-ai/authnpm1HighNot in the registry
@grackle-ai/plugin-corenpm1HighNot in the registry
agentic-flownpm1HighNot in the registry
@agenticmail/mcpnpm1HighNot in the registry
anthropics/claude-code-actionactions1MediumNot in the registry
github.com/safedep/gryphGo1MediumNot in the registry
@yoda.digital/gitlab-mcp-servernpm1CriticalNot in the registry
@penpot/mcpnpm1HighNot in the registry
9routernpm1CriticalNot in the registry
github.com/envoyproxy/ai-gatewayGo1MediumNot in the registry
auth-fetch-mcpnpm1HighNot in the registry
apmPyPI1HighNot in the registry
paperclipainpm1CriticalNot in the registry
agixtPyPI1HighNot in the registry
io-modelcontextprotocol-sdk:mcp-coremaven1HighNot in the registry
@mobilenext/mobile-mcpnpm1HighNot in the registry
openclawnpm1HighNot in the registry
adx-mcp-serverPyPI1HighNot in the registry
github.com/tencent/weknoraGo1MediumNot in the registry
github.com/agentgateway/agentgatewayGo1MediumNot in the registry
@github/copilotnpm1HighNot in the registry

Topics are assigned by matching a record's title and summary against published patterns, so an advisory that never uses the words is missed and one that mentions them in passing is counted. An advisory that names several packages counts once for each. A package is listed with the ecosystem its advisory source states, and by name alone when the source states none.

Authority is read from the dependencies a package's latest release declares, and it is known only for packages the Exposure Registry tracks. It shows what a package's dependencies can do on the host. It does not show that a model is given that reach. Severity comes from the source advisory when it gives one, otherwise from the classifier. Dates are in UTC.