Skip to content

MCP and agent packages

The packages that advisories about the Model Context Protocol and AI agents name, with what the Exposure Registry knows about each one: the LLM components it declares and the authority its dependencies grant (shell, files, browser, network, code execution).

Advisories are grouped by topic. The Model Context Protocol view counts the records that match that topic, and the AI agents view counts those that match the AI agents or the agent-to-agent protocols topic. Package names are those the advisory source lists. How authority is measured

Advisories
198
Critical or high
148
Packages named
77
Advisories listed as exploited (CISA KEV)
2

99 advisories were published in the last 90 days and 50 in the 90 days before. 64 of the 198 name no package, because their source lists none.

Advisories by month of publication

May 2025: 11May 2025Jun 2025: 2Jul 2025: 4Aug 2025: 1Sep 2025: 2Oct 2025: 3Nov 2025: 0Dec 2025: 4Jan 2026: 4Jan 2026Feb 2026: 5Mar 2026: 18Apr 2026: 16May 2026: 19Jun 2026: 13Jul 2026: 28Aug 2026: 3636Sep 2026: 31Oct 2026: 1111Oct 2026
Advisories in this view, per month of publication
MonthItems
May 20251
Jun 20252
Jul 20254
Aug 20251
Sep 20252
Oct 20253
Nov 20250
Dec 20254
Jan 20264
Feb 20265
Mar 202618
Apr 202616
May 202619
Jun 202613
Jul 202628
Aug 202636
Sep 202631
Oct 202611

Authority in the registry

81 registry packages declare the MCP SDK or FastMCP. Their dependencies grant:

  • MCP tools74Exposes or calls Model Context Protocol tools, which pass authority between agents and servers.
  • Outbound HTTP38Makes outbound requests, the precondition for server-side request forgery and exfiltration.
  • File system9Reads or writes files, so path traversal and data exposure are in reach.
  • Browser control7Drives a browser, so it can act on websites with the user's sessions.
  • Code execution7Runs code it is given, so injected instructions can become arbitrary code.
  • Shell commands3Starts processes on the host, the most direct path from a prompt to the operating system.

Packages that declare the MCP SDK, in the Exposure Registry

Advisories that name mcp-memory-keeper

Close

npm. Every record that names the package, on any topic, newest first. RSS feed for this package

Packages named in advisories

77 packages

Packages named in advisories of this view, with their advisory count and registry entry
PackageAdvisoriesHighest severityLatest advisoryExploitedAuthority
stata-mcpPyPI1HighNot in the registry
gemini-bridgePyPI1MediumNot in the registry
mcp-memory-keepernpm1MediumNot in the registry
langbotPyPI1HighNot in the registry
phantom-audioPyPI1HighNot in the registry
github.com/coder/coder/v2Go1MediumNot in the registry
@grackle-ai/authnpm1HighNot in the registry
@grackle-ai/plugin-corenpm1HighNot in the registry
agentic-flownpm1HighNot in the registry
anthropics/claude-code-actionactions1MediumNot in the registry
@yoda.digital/gitlab-mcp-servernpm1CriticalNot in the registry
@penpot/mcpnpm1HighNot in the registry
9routernpm1CriticalNot in the registry
github.com/envoyproxy/ai-gatewayGo1MediumNot in the registry
auth-fetch-mcpnpm1HighNot in the registry
@openai/codexnpm1HighNot in the registry
io-modelcontextprotocol-sdk:mcp-coremaven1HighNot in the registry
@mobilenext/mobile-mcpnpm1HighNot in the registry
adx-mcp-serverPyPI1HighNot in the registry
github.com/tencent/weknoraGo1MediumNot in the registry
github.com/agentgateway/agentgatewayGo1MediumNot in the registry
@github/copilotnpm1HighNot in the registry
mcp-run-pythonPyPI1MediumNot in the registry
@lobehub/chatnpm1MediumNot in the registry
github.com/1panel-dev/1panel/coreGo1HighNot in the registry
@cyanheads/git-mcp-servernpm1HighNot in the registry
ios-simulator-mcpnpm1MediumNot in the registry

Topics are assigned by matching a record's title and summary against published patterns, so an advisory that never uses the words is missed and one that mentions them in passing is counted. An advisory that names several packages counts once for each. A package is listed with the ecosystem its advisory source states, and by name alone when the source states none.

Authority is read from the dependencies a package's latest release declares, and it is known only for packages the Exposure Registry tracks. It shows what a package's dependencies can do on the host. It does not show that a model is given that reach. Severity comes from the source advisory when it gives one, otherwise from the classifier. Dates are in UTC.