Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- This bridge implicitly downloads/executes an external npm package via `npx` and immediately connects it to a remote MCP endpoint, while piping local stdin/stdout through the spawned process. That creates a supply-chain and data-exfiltration boundary crossing without explicit user consent, version integrity verification, or local vendoring, so a compromised package, registry response, or remote service could process sensitive prompts and tool traffic.
