Skip to content

MCP and agent packages

The packages that advisories about the Model Context Protocol and AI agents name, with what the Exposure Registry knows about each one: the LLM components it declares and the authority its dependencies grant (shell, files, browser, network, code execution).

Advisories are grouped by topic. The Model Context Protocol view counts the records that match that topic, and the AI agents view counts those that match the AI agents or the agent-to-agent protocols topic. Package names are those the advisory source lists. How authority is measured

Advisories
160
Critical or high
106
Packages named
44
Advisories listed as exploited (CISA KEV)
0

51 advisories were published in the last 90 days and 37 in the 90 days before. 74 of the 160 name no package, because their source lists none.

Advisories by month of publication

May 2025: 11May 2025Jun 2025: 4Jul 2025: 2Aug 2025: 5Sep 2025: 10Oct 2025: 4Nov 2025: 3Dec 2025: 4Jan 2026: 6Jan 2026Feb 2026: 14Mar 2026: 13Apr 2026: 9May 2026: 2424Jun 2026: 4Jul 2026: 17Aug 2026: 17Sep 2026: 17Oct 2026: 44Oct 2026
Advisories in this view, per month of publication
MonthItems
May 20251
Jun 20254
Jul 20252
Aug 20255
Sep 202510
Oct 20254
Nov 20253
Dec 20254
Jan 20266
Feb 202614
Mar 202613
Apr 20269
May 202624
Jun 20264
Jul 202617
Aug 202617
Sep 202617
Oct 20264

Authority in the registry

282 registry packages declare an agent framework. Their dependencies grant:

  • Outbound HTTP105Makes outbound requests, the precondition for server-side request forgery and exfiltration.
  • MCP tools49Exposes or calls Model Context Protocol tools, which pass authority between agents and servers.
  • File system23Reads or writes files, so path traversal and data exposure are in reach.
  • Browser control16Drives a browser, so it can act on websites with the user's sessions.
  • Code execution14Runs code it is given, so injected instructions can become arbitrary code.
  • Shell commands4Starts processes on the host, the most direct path from a prompt to the operating system.

All packages in the Exposure Registry

Advisories that name openclaw

Close

npm. Every record that names the package, on any topic, newest first. RSS feed for this package

Packages named in advisories

44 packages

Packages named in advisories of this view, with their advisory count and registry entry
PackageAdvisoriesHighest severityLatest advisoryExploitedAuthority
@anthropic-ai/claude-codenpm22CriticalNot in the registry
github.com/pinchtab/pinchtabGo6HighNot in the registry
github.com/hatchet-dev/hatchetGo5MediumNot in the registry
pydantic-aiPyPI4HighNone detected
pydantic-ai-slimPyPI4HighOutbound HTTP
omnigentPyPI4CriticalNot in the registry
n8nnpm4HighCode execution, File system, MCP tools, Shell commands
@evomap/evolvernpm3CriticalNot in the registry
github.com/pinchtab/pinchtab/cmd/pinchtabGo3HighNot in the registry
@ooples/token-optimizer-mcpnpm2HighNot in the registry
@agenticmail/corenpm2HighNot in the registry
@agenticmail/apinpm2HighNot in the registry
apm-cliPyPI2HighNot in the registry
@paperclipai/servernpm2CriticalNot in the registry
@enclave-vm/corenpm2CriticalNot in the registry
enclave-vmnpm2CriticalNot in the registry
opencode-ainpm2HighNot in the registry
neuron-core/neuron-aicomposer2CriticalNot in the registry
hatchetGo1HighNot in the registry
hatchet-dev/hatchetGo1MediumNot in the registry
@andrea9293/mcp-documentation-servernpm1HighNot in the registry
@apify/actors-mcp-servernpm1HighNot in the registry
@trigger.dev/corenpm1HighNot in the registry
@jshookmcp/jshooknpm1MediumNot in the registry
n8nEcosystem not stated1HighNot in the registry
@agenticmail/claudecodenpm1HighNot in the registry
@agenticmail/codexnpm1HighNot in the registry
@agenticmail/openclawnpm1HighNot in the registry
agentic-flownpm1HighNot in the registry
@agenticmail/mcpnpm1HighNot in the registry
praisonaiPyPI1CriticalNot in the registry
github.com/safedep/gryphGo1MediumNot in the registry
@yoda.digital/gitlab-mcp-servernpm1CriticalNot in the registry
apmPyPI1HighNot in the registry
paperclipainpm1CriticalNot in the registry
agixtPyPI1HighNot in the registry
openclawnpm1HighNot in the registry
langflowPyPI1CriticalNone detected
github.com/agentgateway/agentgatewayGo1MediumNot in the registry
microsoft-semantickernel-corenuget1CriticalNot in the registry
semantic-kernelPyPI1CriticalOutbound HTTP, MCP tools
@mastra/mcp-docs-servernpm1MediumNot in the registry
@openai/codexnpm1HighNot in the registry
khojPyPI1MediumCode execution, Outbound HTTP

Topics are assigned by matching a record's title and summary against published patterns, so an advisory that never uses the words is missed and one that mentions them in passing is counted. An advisory that names several packages counts once for each. A package is listed with the ecosystem its advisory source states, and by name alone when the source states none.

Authority is read from the dependencies a package's latest release declares, and it is known only for packages the Exposure Registry tracks. It shows what a package's dependencies can do on the host. It does not show that a model is given that reach. Severity comes from the source advisory when it gives one, otherwise from the classifier. Dates are in UTC.