Missing User Warnings
- Category
- Not specified by scanner
- Confidence
- 92% confidence
- Finding
This bridge implicitly downloads/executes an external npm package via
npxand immediately connects it to a remote MCP endpoint, while piping local stdin/stdout through the spawned process. That creates a supply-chain and data-exfiltration boundary crossing without explicit user consent, version integrity verification, or local vendoring, so a compromised package, registry response, or remote service could process sensitive prompts and tool traffic.- Content
