T08 · Insecure Dependencies
- Location
README.md:53- Finding
Unaudited External CLI and MCP Components Are Installed and Executed
- Content
View full analysis
**Nota de seguridad:** el CLI y el MCP server se instalan desde npm/GitHub y contienen código fuente que no forma parte del artefacto revisado en ClawHub. Revisa el [repositorio](https://github.com/SitoSt/bilingual-humanicer) antes de instalar, y usa una versión pinada si lo integras en entornos de producción. ```bash npm install -g bilingual-humanizer@3.2.0 humanizer --help ``` O sin instalación global: ```bash git clone https://github.com/SitoSt/bilingual-humanicer.git cd bilingual-humanicer && npm install node src/cli/index.js --help ``` ``` `package.json:5-15`: ```json "files": [ "src/", "mcp-server/", "README.md", "CHANGELOG.md", "LICENSE" ], "main": "src/core/analyzer.js", "bin": { "humanizer": "src/cli/index.js" }, ``` ### Technical Analysis The package manifest and documentation describe executable entry points under `src/` and `mcp-server/`, but neither directory exists in the reviewed project. The autonomous knowledge files can be assessed, while the promoted CLI and MCP impleme ...[truncated 3261 chars]- Remediation
View remediation
