# Security Audit Report — ainative-memory-mcp

- **Report ID:** `9b13662e-d2b1-4df8-90d3-7be5cbabc886`
- **Generated:** 2026-08-02T08:28:04.649022+00:00
- **Signature:** unsigned (cosign keyless signing runs in CI; Req 22.4)

## 1. Executive Summary

**Badge:** Unsafe (composite)  
**Security score:** 32.38

| Scanner | Badge |
| --- | --- |
| agent-audit-kit | Unsafe |
| agentshield | Verified |
| cisco-skill-scanner | Verified |
| nerlo-behavioral | Unsafe |
| nerlo-install-instruction | Verified |
| nerlo-multi-source | Verified |
| osv-scanner | Unsafe |
| trivy | Unsafe |

| Severity | Findings |
| --- | --- |
| critical | 15 |
| high | 20 |
| medium | 27 |
| low | 4 |
| informational | 19 |

ainative-memory-mcp is NOT recommended for integration: the scan surfaced 15 critical and 20 high-severity findings. Treat the Per-Scanner Detail section as a remediation worklist and re-scan before reconsidering.

## 2. Source Provenance

- **Repository:** https://github.com/AINative-Studio/ainative-memory-mcp
- **Commit scanned:** `unknown`
- **License:** MIT
- **Maintainer:** AINative Studio
- **Version:** 1.0.1

## 3. Per-Scanner Detail

### agentshield (v1.4.0) — Verified / 100.0

No findings.

### cisco-skill-scanner (v2.0.11) — Verified / 88.5

- **[informational] Moderate analyzability score** — [mcp_server policy: capability-matches-purpose class; severity medium -> informational] Only 86% of skill content could be analyzed. 1 of 10 files are opaque to the scanner. Some content could not be verified as safe. (/repo:None)
- **[low] Hidden data file detected** — Hidden file found: .cody/CODY.md. Hidden files may contain concealed configuration or data that should be reviewed. (/repo/.cody/CODY.md:None)
- **[informational] Vague skill description** — [mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation. (/repo/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/SKILL.md:None)
- **[informational] Outbound network request primitives in JavaScript/TypeScript** — [mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post( (/repo/index.js:191)
- **[informational] Outbound network request primitives in JavaScript/TypeScript** — [mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post( (/repo/index.js:201)
- **[informational] Outbound network request primitives in JavaScript/TypeScript** — [mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post( (/repo/index.js:224)
- **[informational] Outbound network request primitives in JavaScript/TypeScript** — [mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post( (/repo/index.js:245)
- **[informational] Outbound network request primitives in JavaScript/TypeScript** — [mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post( (/repo/index.js:269)
- **[informational] Outbound network request primitives in JavaScript/TypeScript** — [mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post( (/repo/index.js:285)
- **[informational] Outbound network request primitives in JavaScript/TypeScript** — [mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.request( (/repo/index.js:303)
- **[informational] Outbound network request primitives in JavaScript/TypeScript** — [mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.request( (/repo/index.js:316)
- **[informational] Outbound network request primitives in JavaScript/TypeScript** — [mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post( (/repo/index.js:330)
- **[informational] Outbound network request primitives in JavaScript/TypeScript** — [mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post( (/repo/index.js:449)
- **[informational] Vague skill description** — [mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation. (/repo/.cody/SKILL.md:None)
- **[informational] Skill name does not follow agent skills naming rules** — Skill name '.cody' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters. (/repo/.cody/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/.cody/SKILL.md:None)
- **[informational] Vague skill description** — [mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation. (/repo/.claude/SKILL.md:None)
- **[informational] Skill name does not follow agent skills naming rules** — Skill name '.claude' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters. (/repo/.claude/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/.claude/SKILL.md:None)

### agent-audit-kit (v0.3.26) — Unsafe / 0.0

- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (.claude/CLAUDE.md:10)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (.claude/CLAUDE.md:11)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (.claude/CLAUDE.md:12)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (.claude/CLAUDE.md:13)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (.claude/CLAUDE.md:14)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (.claude/CLAUDE.md:15)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (.claude/CLAUDE.md:16)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (.claude/CLAUDE.md:17)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (.claude/CLAUDE.md:18)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (.claude/CLAUDE.md:23)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (.claude/CLAUDE.md:23)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (.claude/CLAUDE.md:17)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (.claude/CLAUDE.md:16)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (.claude/CLAUDE.md:18)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (.claude/CLAUDE.md:None)
- **[low] MCP server repo missing SECURITY.md or security_contact** — A repository whose name or pyproject keywords declare it as an MCP server ships without a top-level SECURITY.md AND without a 'security_contact' entry in marketplace.json / pyproject.toml / package.json. Anthropic's April 2026 SECURITY.md guidance makes this the baseline expectation so researchers have a channel. (SECURITY.md:None)
- **[medium] Repo depends on a third-party agent-platform SDK** — The project depends on an agent-platform SDK (context-ai, langsmith, helicone, langfuse, humanloop, MCP SDK). Informational finding so reviewers audit the vendor's OAuth-scope footprint before merging. Raised to MEDIUM because the April 19 2026 Vercel × Context.ai incident showed a single vendor compromise can turn into a production breach via transitive OAuth grants. (package.json:74)
- **[high] MCP server built on the upstream SDK without STDIO sanitizer** — Repository declares a dependency on the upstream Anthropic / ModelContextProtocol SDK (Python 'mcp' / 'modelcontextprotocol', TS '@modelcontextprotocol/sdk', Java 'io.modelcontextprotocol:*', Rust 'mcp' / 'modelcontextprotocol') and exposes a STDIO transport ('StdioServerTransport', 'stdio_server', etc.) without a sanitizer on argv assembly. Anthropic declined to CVE this as working as designed — sanitization is the developer's responsibility. The OX Security disclosure on 2026-04-15 rolled up L (index.js:None)
- **[high] Session token written to log sink in cleartext** — An MCP server, agent, or tool logs a session token, JWT, or Bearer credential through a generic log sink (logger.info / .warn / .error, print) without redaction. CVE-2026-20205 (splunk-mcp-server < 1.0.3) shipped this exact pattern — session tokens ended up in the Splunk '_internal' index, readable by anyone with index-read. Any token written to a log sink is also a supply-chain risk: the log file, shipper, and SIEM are now in scope for the token's blast radius. (index.js:145)

### nerlo-behavioral (v0.1.0) — Unsafe / 0.0

- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/index.js:191)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/index.js:201)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/index.js:224)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/index.js:245)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/index.js:269)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/index.js:285)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/index.js:303)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/index.js:316)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/index.js:330)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/index.js:449)

### nerlo-install-instruction (v0.1.0) — Verified / 100.0

No findings.

### nerlo-multi-source (v0.1.0) — Verified / 100.0

No findings.

### trivy (v0.71.0) — Unsafe / 0.0

- **[medium] Node.js Adapter for Hono: Path traversal in 'serve-static' on Windows via encoded backslash ('%5C')** — The same as the 'hono' core [Path traversal in 'serve-static' on Windows via encoded backslash ('%5C')](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).  \#\#\# Summary  On Windows hosts, an encoded backslash ('%5C') in the request path decodes to '\', which the Windows path resolver treats as a separator. 'serve-static' then resolves a single URL segment such as 'admin\secret.txt' into a nested file under the root and serves it, letting an attacker read static files meant t (package-lock.json:None)
- **[high] Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning** — \#\# Summary  Axios’ Node.js HTTP adapter can route requests through an attacker-controlled proxy when 'Object.prototype.proxy' is polluted and request configuration is materialized as a regular object before dispatch.  Recent axios releases harden merged request config by creating a null-prototype object. However, request interceptors run after that merge and may return a replacement config. A common immutable interceptor pattern such as '{...config}' or 'Object.assign({}, config)' converts the h (package-lock.json:None)
- **[medium] Axios: Excessive recursion in formDataToJSON can cause denial of service** — \#\# Summary Axios versions '0.28.0' and later contain uncontrolled recursion in 'formDataToJSON', the helper behind the public 'axios.formToJSON()' / named 'formToJSON' API and the default request transform used when FormData is sent with an 'application/json' content type.  Applications are affected when they pass attacker-controlled 'FormData' field names into this functionality. A field name with thousands of nested bracket segments can exhaust the JavaScript call stack and throw 'RangeError:  (package-lock.json:None)
- **[medium] Axios: Nested axios option objects can consume polluted prototype values** — \#\# Summary  Axios can consume inherited properties from nested request option objects when the JavaScript process already has a polluted 'Object.prototype'.  The top-level merged config is protected with a null prototype, but nested plain objects such as 'auth' and 'paramsSerializer' are cloned into ordinary objects. If application code passes placeholders such as 'auth: {}' or 'paramsSerializer: {}', inherited 'username', 'password', 'encode', or 'serialize' properties can influence outbound re (package-lock.json:None)
- **[medium] Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios** — \#\# Summary  Axios versions containing 'lib/helpers/shouldBypassProxy.js' do not treat '0.0.0.0' as a local address when evaluating 'NO_PROXY' rules. In Node.js applications that use 'HTTP_PROXY' or 'HTTPS_PROXY' together with 'NO_PROXY=localhost,127.0.0.1,::1' or similar, a request to 'http://0.0.0.0:<port>/' can be routed through the configured proxy instead of bypassing it.  The issue is exploitable when an attacker can influence the axios request URL or a followed redirect target, and when th (package-lock.json:None)
- **[medium] Axios form serializer maxDepth bypass via {} metatoken** — \#\# Summary  Axios versions in the fixed lines for GHSA-62hf-57xw-28j9 still contain an incomplete depth-limit bypass in 'lib/helpers/toFormData.js'. When serializing an object with a top-level key ending in '{}', axios calls 'JSON.stringify()' on that value before the 'formSerializer.maxDepth' guard can inspect the nested structure.  An attacker who can control object keys and nested values passed by an application into axios form or parameter serialization can trigger a raw 'RangeError: Maximum (package-lock.json:None)
- **[medium] Axios: Fetch adapter 'ReadableStream' uploads bypass 'maxBodyLength'** — \#\# Summary  axios’ fetch adapter does not enforce 'maxBodyLength' for live WHATWG 'ReadableStream' request bodies whose size cannot be determined before dispatch. Applications that use 'adapter: "fetch"' and rely on 'maxBodyLength' to cap untrusted upload/proxy streams can send the full stream even when it exceeds the configured limit.  This affects fetch-adapter usage in edge runtimes where fetch is selected, and in Node.js or browser environments where the fetch adapter is explicitly selected. (package-lock.json:None)
- **[medium] Axios: Prototype pollution gadgets can alter axios request construction** — \#\# Summary  axios is vulnerable to read-side prototype-pollution gadgets when 'Object.prototype' has already been polluted by another vulnerability or dependency. The most broadly reachable issue is in the bodyless method aliases: 'axios.get()', 'axios.delete()', 'axios.head()', and 'axios.options()' read inherited 'data' before config normalization, causing attacker-controlled body data to be sent on requests that did not explicitly set a body.  Additional low-level paths affect consumers that  (package-lock.json:None)
- **[medium] Axios: HTTP/2 streamed uploads bypass 'maxBodyLength'** — \#\# Summary  Axios versions with Node.js HTTP/2 support allow streamed request bodies to bypass 'maxBodyLength' enforcement when requests are sent with 'httpVersion: 2'.  This affects applications that rely on 'maxBodyLength' as a hard cap while forwarding attacker-controlled streams, such as upload endpoints proxying user data to an upstream HTTP/2 service. Buffered request bodies are still checked before the request is sent.  \#\# Impact  An attacker who can control a stream passed to axios can c (package-lock.json:None)
- **[medium] Axios: Deep formToJSON Key Recursion Can Cause Denial of Service** — \#\# Summary  Axios versions starting with '0.28.0' contain uncontrolled recursion in 'formDataToJSON', which is exposed as 'axios.formToJSON()' and used internally when axios serialises 'FormData' with 'Content-Type: application/json'.  If an application passes attacker-controlled 'FormData' field names to this functionality, a field name with thousands of nested bracket segments can exhaust the JavaScript call stack and cause denial of service for that request or, in applications without appropr (package-lock.json:None)
- **[medium] Axios: Prototype pollution auth subfields can inject Basic auth** — \#\# Summary  Axios versions after the 'GHSA-q8qp-cvcw-x6jj' fix still contain prototype-pollution read-side gadgets in Basic auth subfield handling. If a host application is already affected by prototype pollution and then makes an axios request with an own 'auth' object that omits 'username' or 'password', axios reads inherited 'Object.prototype.username' and 'Object.prototype.password' values and uses them to construct an outbound 'Authorization: Basic ...' header.  This does not mean axios its (package-lock.json:None)
- **[low] body-parser: body-parser: Denial of Service via invalid limit option** — Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars (package-lock.json:None)
- **[high] fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization** — fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo (package-lock.json:None)
- **[high] Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...** — Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f (package-lock.json:None)
- **[high] form-data: form-data: Form field override via CRLF injection** — form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the 'field' argument to 'FormData\#append' and the 'filename' option are concatenated verbatim into the 'Content-Disposition' header without escaping carriage return (CR), line feed (LF), or double-quote (") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the atta (package-lock.json:None)
- **[medium] hono: Hono: Arbitrary markup injection via improper handling of class names in server-side rendering.** — Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27. (package-lock.json:None)
- **[medium] hono: Hono: Information disclosure due to improper context isolation in server-side rendering** — Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27. (package-lock.json:None)
- **[medium] hono: Hono: Information disclosure due to incorrect header de-duplication in AWS API Gateway v1 adapter** — Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27. (package-lock.json:None)

### osv-scanner (v2.3.8) — Unsafe / 0.0

- **[medium] GHSA-frvp-7c67-39w9 — npm @hono/node-server@1.19.14** — aliases: GHSA-frvp-7c67-39w9 \| CVSS: 5.9 (/repo/package-lock.json:None)
- **[medium] GHSA-42h9-826w-cgv3 — npm axios@1.17.0** — aliases: GHSA-42h9-826w-cgv3 \| CVSS: 6.3 (/repo/package-lock.json:None)
- **[medium] GHSA-7q8q-rj6j-mhjq — npm axios@1.17.0** — aliases: GHSA-7q8q-rj6j-mhjq \| CVSS: 6.3 (/repo/package-lock.json:None)
- **[medium] GHSA-f4gw-2p7v-4548 — npm axios@1.17.0** — aliases: GHSA-f4gw-2p7v-4548 \| CVSS: 6.9 (/repo/package-lock.json:None)
- **[high] GHSA-gcfj-64vw-6mp9 — npm axios@1.17.0** — aliases: GHSA-gcfj-64vw-6mp9 \| CVSS: 8.3 (/repo/package-lock.json:None)
- **[medium] GHSA-hcpx-6fm6-wx23 — npm axios@1.17.0** — aliases: GHSA-hcpx-6fm6-wx23 \| CVSS: 6.9 (/repo/package-lock.json:None)
- **[medium] GHSA-jqh4-m9w3-8hp9 — npm axios@1.17.0** — aliases: GHSA-jqh4-m9w3-8hp9 \| CVSS: 6.3 (/repo/package-lock.json:None)
- **[medium] GHSA-mmx7-hfxf-jppx — npm axios@1.17.0** — aliases: GHSA-mmx7-hfxf-jppx \| CVSS: 6.3 (/repo/package-lock.json:None)
- **[medium] GHSA-mwf2-3pr3-8698 — npm axios@1.17.0** — aliases: GHSA-mwf2-3pr3-8698 \| CVSS: 6.3 (/repo/package-lock.json:None)
- **[medium] GHSA-pmv8-rq9r-6j72 — npm axios@1.17.0** — aliases: GHSA-pmv8-rq9r-6j72 \| CVSS: 6.3 (/repo/package-lock.json:None)
- **[medium] GHSA-xj6q-8x83-jv6g — npm axios@1.17.0** — aliases: GHSA-xj6q-8x83-jv6g \| CVSS: 6.3 (/repo/package-lock.json:None)
- **[low] GHSA-v422-hmwv-36x6 — npm body-parser@2.2.2** — aliases: CVE-2026-12590, GHSA-v422-hmwv-36x6 \| CVSS: 3.7 (/repo/package-lock.json:None)
- **[high] GHSA-4c8g-83qw-93j6 — npm fast-uri@3.1.2** — aliases: CVE-2026-13676, GHSA-4c8g-83qw-93j6 \| CVSS: 7.5 (/repo/package-lock.json:None)
- **[high] GHSA-v2hh-gcrm-f6hx — npm fast-uri@3.1.2** — aliases: CVE-2026-16221, GHSA-v2hh-gcrm-f6hx \| CVSS: 7.5 (/repo/package-lock.json:None)
- **[high] GHSA-hmw2-7cc7-3qxx — npm form-data@4.0.5** — aliases: CVE-2026-12143, GHSA-hmw2-7cc7-3qxx \| CVSS: 8.7 (/repo/package-lock.json:None)
- **[medium] GHSA-hvrm-45r6-mjfj — npm hono@4.12.25** — aliases: CVE-2026-59896, GHSA-hvrm-45r6-mjfj \| CVSS: 6.5 (/repo/package-lock.json:None)
- **[medium] GHSA-w62v-xxxg-mg59 — npm hono@4.12.25** — aliases: CVE-2026-59895, GHSA-w62v-xxxg-mg59 \| CVSS: 6.1 (/repo/package-lock.json:None)
- **[medium] GHSA-xgm2-5f3f-mvvc — npm hono@4.12.25** — aliases: CVE-2026-59897, GHSA-xgm2-5f3f-mvvc \| CVSS: 4.8 (/repo/package-lock.json:None)

## 4. Threat Model

Threat model synthesis has not yet run for this scan. This section is generated by the registry's LLM pipeline (Req 22.3) and will appear in the next regeneration of this report.

## 5. Audit Chain

- **Scan job:** `3b1c2b65-8b92-49ea-9098-759d2a6b9a97`
- **Completed:** 2026-08-01T07:44:03.293405+00:00
- **Scanner base image:** `us-central1-docker.pkg.dev/nerlo-vsk-prod/nerlo/scanner-base@sha256:5b605cdef65aaf3d8b562c388cdd6483d6922974476d23c1f8e4f6c5f6ae723e`
- **AI decision log entries:** 2
  - `b3c1e102-e39d-472e-9224-14e8fc5e24d1`
  - `91e2ff05-818e-402f-853b-2e03a072fc93`

## 6. Appendix — Raw Scanner Output

```json
[
  {
    "scanner_name": "agentshield",
    "scanner_version": "1.4.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 2.7017520390218124,
    "status": "complete",
    "examined": null,
    "metadata": {
      "source": "npm",
      "source_url": "https://www.npmjs.com/package/ecc-agentshield",
      "install_command": "npm install -g ecc-agentshield@1.4.0",
      "scans_performed": [
        "claude_config",
        "supply_chain"
      ],
      "score_breakdown": {
        "mcp": 100,
        "hooks": 100,
        "agents": 100,
        "secrets": 100,
        "permissions": 100
      }
    },
    "display_score": 100.0,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "cisco-skill-scanner",
    "scanner_version": "2.0.11",
    "score": 88.5,
    "scanner_badge": "Verified",
    "findings": [
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "[mcp_server policy: capability-matches-purpose class; severity medium -> informational] Only 86% of skill content could be analyzed. 1 of 10 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "obfuscation",
        "file_path": "/repo/.cody/CODY.md",
        "line_number": null,
        "rule_identifier": "HIDDEN_DATA_FILE",
        "title": "Hidden data file detected",
        "description": "Hidden file found: .cody/CODY.md. Hidden files may contain concealed configuration or data that should be reviewed.",
        "remediation": "Move file to a visible location or document its purpose."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "social_engineering",
        "file_path": "/repo/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "data_exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 191,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "[mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "data_exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 201,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "[mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "data_exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 224,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "[mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "data_exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 245,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "[mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "data_exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 269,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "[mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "data_exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 285,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "[mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "data_exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 303,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "[mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.request(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "data_exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 316,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "[mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.request(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "data_exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 330,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "[mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "data_exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 449,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "[mcp_server policy: capability-matches-purpose class; severity medium -> informational] Pattern detected: axios.post(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "social_engineering",
        "file_path": "/repo/.cody/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/.cody/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_INVALID_NAME",
        "title": "Skill name does not follow agent skills naming rules",
        "description": "Skill name '.cody' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
        "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/.cody/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "social_engineering",
        "file_path": "/repo/.claude/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/.claude/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_INVALID_NAME",
        "title": "Skill name does not follow agent skills naming rules",
        "description": "Skill name '.claude' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
        "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/.claude/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      }
    ],
    "execution_duration_seconds": 11.312457343999995,
    "status": "complete",
    "examined": {
      "unit": "skills",
      "count": 3
    },
    "metadata": {
      "source": "pypi",
      "source_url": "https://pypi.org/project/cisco-ai-skill-scanner/2.0.11/",
      "report_type": "cisco-skill-sast",
      "analyzers_used": [
        "bytecode",
        "pipeline",
        "static_analyzer"
      ],
      "skills_scanned": [
        "repo",
        ".cody",
        ".claude"
      ],
      "install_command": "pip install --require-hashes -r docker/scanner-base/cisco-skill-scanner/requirements.txt",
      "severity_counts": {
        "low": 1,
        "high": 0,
        "medium": 0,
        "critical": 0,
        "informational": 19
      },
      "artifact_type_policy": "mcp_server",
      "downweighted_findings": 14
    },
    "display_score": 88.5,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "agent-audit-kit",
    "scanner_version": "0.3.26",
    "score": 0.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": ".claude/CLAUDE.md",
        "line_number": 10,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": ".claude/CLAUDE.md",
        "line_number": 11,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": ".claude/CLAUDE.md",
        "line_number": 12,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": ".claude/CLAUDE.md",
        "line_number": 13,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": ".claude/CLAUDE.md",
        "line_number": 14,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": ".claude/CLAUDE.md",
        "line_number": 15,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": ".claude/CLAUDE.md",
        "line_number": 16,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": ".claude/CLAUDE.md",
        "line_number": 17,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": ".claude/CLAUDE.md",
        "line_number": 18,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": ".claude/CLAUDE.md",
        "line_number": 23,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": ".claude/CLAUDE.md",
        "line_number": 23,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": ".claude/CLAUDE.md",
        "line_number": 17,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": ".claude/CLAUDE.md",
        "line_number": 16,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": ".claude/CLAUDE.md",
        "line_number": 18,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": ".claude/CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "low",
        "category": "supply-chain",
        "file_path": "SECURITY.md",
        "line_number": null,
        "rule_identifier": "AAK-SEC-MD-001",
        "title": "MCP server repo missing SECURITY.md or security_contact",
        "description": "A repository whose name or pyproject keywords declare it as an MCP server ships without a top-level SECURITY.md AND without a `security_contact` entry in marketplace.json / pyproject.toml / package.json. Anthropic's April 2026 SECURITY.md guidance makes this the baseline expectation so researchers have a channel.",
        "remediation": "Add SECURITY.md at the repo root with a disclosure email and response SLA; OR add `security_contact` to the project manifest."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "supply-chain",
        "file_path": "package.json",
        "line_number": 74,
        "rule_identifier": "AAK-OAUTH-3P-001",
        "title": "Repo depends on a third-party agent-platform SDK",
        "description": "The project depends on an agent-platform SDK (context-ai, langsmith, helicone, langfuse, humanloop, MCP SDK). Informational finding so reviewers audit the vendor's OAuth-scope footprint before merging. Raised to MEDIUM because the April 19 2026 Vercel \u00d7 Context.ai incident showed a single vendor compromise can turn into a production breach via transitive OAuth grants.",
        "remediation": "Pin the SDK to an exact version, audit the OAuth scopes it requests, and keep any deployment-level grants (Vercel, GCP, Workspace) in a secrets vault \u2014 never in a committed env file. See Vercel's bulletin for sensitive-env-var guidance: https://vercel.com/kb/bulletin/vercel-april-2026-security-incident"
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": "index.js",
        "line_number": null,
        "rule_identifier": "AAK-ANTHROPIC-SDK-001",
        "title": "MCP server built on the upstream SDK without STDIO sanitizer",
        "description": "Repository declares a dependency on the upstream Anthropic / ModelContextProtocol SDK (Python `mcp` / `modelcontextprotocol`, TS `@modelcontextprotocol/sdk`, Java `io.modelcontextprotocol:*`, Rust `mcp` / `modelcontextprotocol`) and exposes a STDIO transport (`StdioServerTransport`, `stdio_server`, etc.) without a sanitizer on argv assembly. Anthropic declined to CVE this as working as designed \u2014 sanitization is the developer's responsibility. The OX Security disclosure on 2026-04-15 rolled up L",
        "remediation": "Wrap every argv the STDIO transport builds in an allow-list sanitizer \u2014 `shlex.quote` in Python, `execFile` with an explicit argv array in Node, equivalent in Java/Rust. OR switch the transport off STDIO (`transports=['http']` / `['sse']`). If you have deliberately accepted the risk, add `accepts_stdio_risk: true` plus a `justification:` field in `.agent-audit-kit.yml`."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "secret-exposure",
        "file_path": "index.js",
        "line_number": 145,
        "rule_identifier": "AAK-SPLUNK-TOKLOG-001",
        "title": "Session token written to log sink in cleartext",
        "description": "An MCP server, agent, or tool logs a session token, JWT, or Bearer credential through a generic log sink (logger.info / .warn / .error, print) without redaction. CVE-2026-20205 (splunk-mcp-server < 1.0.3) shipped this exact pattern \u2014 session tokens ended up in the Splunk `_internal` index, readable by anyone with index-read. Any token written to a log sink is also a supply-chain risk: the log file, shipper, and SIEM are now in scope for the token's blast radius.",
        "remediation": "Redact token-shaped values before logging. Never interpolate a raw `Authorization`, `Bearer`, JWT, `splunkd_session`, or `st-` credential into a log message. Pin `splunk-mcp-server >= 1.0.3`."
      }
    ],
    "execution_duration_seconds": 2.171249978011474,
    "status": "complete",
    "examined": {
      "unit": "files",
      "count": 9
    },
    "metadata": {
      "source": "pypi",
      "source_url": "https://pypi.org/project/agent-audit-kit/0.3.26/",
      "report_type": "agent-audit-kit-sast",
      "install_command": "pip install --require-hashes -r docker/scanner-base/agent-audit-kit/requirements.txt",
      "rules_evaluated": 211,
      "severity_counts": {
        "low": 1,
        "high": 2,
        "medium": 1,
        "critical": 15,
        "informational": 0
      }
    },
    "display_score": 0.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "nerlo-behavioral",
    "scanner_version": "0.1.0",
    "score": 0.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 191,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 201,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 224,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 245,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 269,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 285,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 303,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 316,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 330,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/index.js",
        "line_number": 449,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      }
    ],
    "execution_duration_seconds": 31.194510706001893,
    "status": "complete",
    "examined": {
      "unit": "files",
      "count": 1
    },
    "metadata": {
      "source": "nerlo-original",
      "source_url": "https://github.com/nerlo-ai/nerlo",
      "report_type": "nerlo-behavioral",
      "ruleset_path": "/opt/nerlo-rules/exfiltration.yaml",
      "ruleset_paths": [
        "/opt/nerlo-rules/exfiltration.yaml",
        "/opt/nerlo-rules/clipboard_exfiltration.yaml",
        "/opt/nerlo-rules/rce_endpoint.yaml",
        "/opt/nerlo-rules/taint_egress.yaml"
      ],
      "install_command": "pip install 'semgrep==1.97.0'",
      "severity_counts": {
        "low": 0,
        "high": 10,
        "medium": 0,
        "critical": 0,
        "informational": 0
      },
      "merged_invocation": true
    },
    "display_score": 0.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "nerlo-install-instruction",
    "scanner_version": "0.1.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 31.19469668599777,
    "status": "complete",
    "examined": {
      "unit": "files",
      "count": 3
    },
    "metadata": {
      "source": "nerlo-original",
      "source_url": "https://github.com/nerlo-ai/nerlo",
      "report_type": "nerlo-install-instruction",
      "ruleset_path": "/opt/nerlo-rules/install_instructions.yaml",
      "ruleset_paths": [
        "/opt/nerlo-rules/install_instructions.yaml",
        "/opt/nerlo-rules/cursor_rules.yaml"
      ],
      "install_command": "pip install 'semgrep==1.97.0'",
      "merged_invocation": true
    },
    "display_score": 100.0,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "nerlo-multi-source",
    "scanner_version": "0.1.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 19.45466500299517,
    "status": "complete",
    "examined": null,
    "metadata": {
      "source": "nerlo-original",
      "per_source": [
        {
          "badge": "Verified",
          "label": "npm@1.0.1",
          "score": 100.0,
          "version": "1.0.1",
          "identifier": "ainative-memory-mcp",
          "provenance": "clean",
          "source_type": "npm",
          "artifact_type": "mcp_server",
          "finding_count": 0,
          "malware_status": "complete",
          "injected_rule_ids": []
        }
      ],
      "report_type": "nerlo-multi-source",
      "diverged_sources": [],
      "published_surfaces_scanned": 1
    },
    "display_score": 100.0,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "trivy",
    "scanner_version": "0.71.0",
    "score": 0.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-frvp-7c67-39w9",
        "title": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)",
        "description": "The same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t",
        "remediation": "Upgrade @hono/node-server from 1.19.14 to 2.0.5 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-gcfj-64vw-6mp9",
        "title": "Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning",
        "description": "## Summary\n\nAxios\u2019 Node.js HTTP adapter can route requests through an attacker-controlled proxy when `Object.prototype.proxy` is polluted and request configuration is materialized as a regular object before dispatch.\n\nRecent axios releases harden merged request config by creating a null-prototype object. However, request interceptors run after that merge and may return a replacement config. A common immutable interceptor pattern such as `{...config}` or `Object.assign({}, config)` converts the h",
        "remediation": "Upgrade axios from 1.17.0 to 0.33.0, 1.18.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-42h9-826w-cgv3",
        "title": "Axios: Excessive recursion in formDataToJSON can cause denial of service",
        "description": "## Summary\nAxios versions `0.28.0` and later contain uncontrolled recursion in `formDataToJSON`, the helper behind the public `axios.formToJSON()` / named `formToJSON` API and the default request transform used when FormData is sent with an `application/json` content type.\n\nApplications are affected when they pass attacker-controlled `FormData` field names into this functionality. A field name with thousands of nested bracket segments can exhaust the JavaScript call stack and throw `RangeError: ",
        "remediation": "Upgrade axios from 1.17.0 to 0.33.0, 1.18.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-7q8q-rj6j-mhjq",
        "title": "Axios: Nested axios option objects can consume polluted prototype values",
        "description": "## Summary\n\nAxios can consume inherited properties from nested request option objects when the JavaScript process already has a polluted `Object.prototype`.\n\nThe top-level merged config is protected with a null prototype, but nested plain objects such as `auth` and `paramsSerializer` are cloned into ordinary objects. If application code passes placeholders such as `auth: {}` or `paramsSerializer: {}`, inherited `username`, `password`, `encode`, or `serialize` properties can influence outbound re",
        "remediation": "Upgrade axios from 1.17.0 to 0.33.0, 1.18.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-f4gw-2p7v-4548",
        "title": "Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios",
        "description": "## Summary\n\nAxios versions containing `lib/helpers/shouldBypassProxy.js` do not treat `0.0.0.0` as a local address when evaluating `NO_PROXY` rules. In Node.js applications that use `HTTP_PROXY` or `HTTPS_PROXY` together with `NO_PROXY=localhost,127.0.0.1,::1` or similar, a request to `http://0.0.0.0:<port>/` can be routed through the configured proxy instead of bypassing it.\n\nThe issue is exploitable when an attacker can influence the axios request URL or a followed redirect target, and when th",
        "remediation": "Upgrade axios from 1.17.0 to 1.18.0, 0.33.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-hcpx-6fm6-wx23",
        "title": "Axios form serializer maxDepth bypass via {} metatoken",
        "description": "## Summary\n\nAxios versions in the fixed lines for GHSA-62hf-57xw-28j9 still contain an incomplete depth-limit bypass in `lib/helpers/toFormData.js`. When serializing an object with a top-level key ending in `{}`, axios calls `JSON.stringify()` on that value before the `formSerializer.maxDepth` guard can inspect the nested structure.\n\nAn attacker who can control object keys and nested values passed by an application into axios form or parameter serialization can trigger a raw `RangeError: Maximum",
        "remediation": "Upgrade axios from 1.17.0 to 0.33.0, 1.18.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-jqh4-m9w3-8hp9",
        "title": "Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`",
        "description": "## Summary\n\naxios\u2019 fetch adapter does not enforce `maxBodyLength` for live WHATWG `ReadableStream` request bodies whose size cannot be determined before dispatch. Applications that use `adapter: \"fetch\"` and rely on `maxBodyLength` to cap untrusted upload/proxy streams can send the full stream even when it exceeds the configured limit.\n\nThis affects fetch-adapter usage in edge runtimes where fetch is selected, and in Node.js or browser environments where the fetch adapter is explicitly selected.",
        "remediation": "Upgrade axios from 1.17.0 to 1.18.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-mmx7-hfxf-jppx",
        "title": "Axios: Prototype pollution gadgets can alter axios request construction",
        "description": "## Summary\n\naxios is vulnerable to read-side prototype-pollution gadgets when `Object.prototype` has already been polluted by another vulnerability or dependency. The most broadly reachable issue is in the bodyless method aliases: `axios.get()`, `axios.delete()`, `axios.head()`, and `axios.options()` read inherited `data` before config normalization, causing attacker-controlled body data to be sent on requests that did not explicitly set a body.\n\nAdditional low-level paths affect consumers that ",
        "remediation": "Upgrade axios from 1.17.0 to 1.18.0, 0.33.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-mwf2-3pr3-8698",
        "title": "Axios: HTTP/2 streamed uploads bypass `maxBodyLength`",
        "description": "## Summary\n\nAxios versions with Node.js HTTP/2 support allow streamed request bodies to bypass `maxBodyLength` enforcement when requests are sent with `httpVersion: 2`.\n\nThis affects applications that rely on `maxBodyLength` as a hard cap while forwarding attacker-controlled streams, such as upload endpoints proxying user data to an upstream HTTP/2 service. Buffered request bodies are still checked before the request is sent.\n\n## Impact\n\nAn attacker who can control a stream passed to axios can c",
        "remediation": "Upgrade axios from 1.17.0 to 1.18.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-pmv8-rq9r-6j72",
        "title": "Axios: Deep formToJSON Key Recursion Can Cause Denial of Service",
        "description": "## Summary\n\nAxios versions starting with `0.28.0` contain uncontrolled recursion in `formDataToJSON`, which is exposed as `axios.formToJSON()` and used internally when axios serialises `FormData` with `Content-Type: application/json`.\n\nIf an application passes attacker-controlled `FormData` field names to this functionality, a field name with thousands of nested bracket segments can exhaust the JavaScript call stack and cause denial of service for that request or, in applications without appropr",
        "remediation": "Upgrade axios from 1.17.0 to 0.33.0, 1.18.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-xj6q-8x83-jv6g",
        "title": "Axios: Prototype pollution auth subfields can inject Basic auth",
        "description": "## Summary\n\nAxios versions after the `GHSA-q8qp-cvcw-x6jj` fix still contain prototype-pollution read-side gadgets in Basic auth subfield handling. If a host application is already affected by prototype pollution and then makes an axios request with an own `auth` object that omits `username` or `password`, axios reads inherited `Object.prototype.username` and `Object.prototype.password` values and uses them to construct an outbound `Authorization: Basic ...` header.\n\nThis does not mean axios its",
        "remediation": "Upgrade axios from 1.17.0 to 1.18.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "low",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2026-12590",
        "title": "body-parser: body-parser: Denial of Service via invalid limit option",
        "description": "Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars",
        "remediation": "Upgrade body-parser from 2.2.2 to 1.20.6, 2.3.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2026-13676",
        "title": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization",
        "description": "fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo",
        "remediation": "Upgrade fast-uri from 3.1.2 to 4.0.1, 3.1.3, 2.4.2 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2026-16221",
        "title": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...",
        "description": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f",
        "remediation": "Upgrade fast-uri from 3.1.2 to 2.4.3, 3.1.4, 4.1.1 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2026-12143",
        "title": "form-data: form-data: Form field override via CRLF injection",
        "description": "form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (\") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the atta",
        "remediation": "Upgrade form-data from 4.0.5 to 2.5.6, 3.0.5, 4.0.6 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2026-59895",
        "title": "hono: Hono: Arbitrary markup injection via improper handling of class names in server-side rendering.",
        "description": "Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.",
        "remediation": "Upgrade hono from 4.12.25 to 4.12.27 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2026-59896",
        "title": "hono: Hono: Information disclosure due to improper context isolation in server-side rendering",
        "description": "Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27.",
        "remediation": "Upgrade hono from 4.12.25 to 4.12.27 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2026-59897",
        "title": "hono: Hono: Information disclosure due to incorrect header de-duplication in AWS API Gateway v1 adapter",
        "description": "Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.",
        "remediation": "Upgrade hono from 4.12.25 to 4.12.27 or later"
      }
    ],
    "execution_duration_seconds": 0.4306793189898599,
    "status": "complete",
    "examined": {
      "unit": "manifests",
      "count": 1
    },
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/aquasecurity/trivy/releases/tag/v0.71.0",
      "report_type": "filesystem-vulnerability",
      "install_command": "curl -sfL -o /tmp/trivy.deb https://github.com/aquasecurity/trivy/releases/download/v0.71.0/trivy_0.71.0_Linux-64bit.deb && echo '<sha256>  /tmp/trivy.deb' | sha256sum -c - && dpkg -i /tmp/trivy.deb",
      "severity_counts": {
        "low": 1,
        "high": 4,
        "medium": 13,
        "critical": 0,
        "informational": 0
      },
      "manifests_scanned": [
        "package-lock.json"
      ]
    },
    "display_score": 0.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "osv-scanner",
    "scanner_version": "2.3.8",
    "score": 0.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-frvp-7c67-39w9",
        "title": "GHSA-frvp-7c67-39w9 \u2014 npm @hono/node-server@1.19.14",
        "description": "aliases: GHSA-frvp-7c67-39w9 | CVSS: 5.9",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-42h9-826w-cgv3",
        "title": "GHSA-42h9-826w-cgv3 \u2014 npm axios@1.17.0",
        "description": "aliases: GHSA-42h9-826w-cgv3 | CVSS: 6.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-7q8q-rj6j-mhjq",
        "title": "GHSA-7q8q-rj6j-mhjq \u2014 npm axios@1.17.0",
        "description": "aliases: GHSA-7q8q-rj6j-mhjq | CVSS: 6.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-f4gw-2p7v-4548",
        "title": "GHSA-f4gw-2p7v-4548 \u2014 npm axios@1.17.0",
        "description": "aliases: GHSA-f4gw-2p7v-4548 | CVSS: 6.9",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-gcfj-64vw-6mp9",
        "title": "GHSA-gcfj-64vw-6mp9 \u2014 npm axios@1.17.0",
        "description": "aliases: GHSA-gcfj-64vw-6mp9 | CVSS: 8.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-hcpx-6fm6-wx23",
        "title": "GHSA-hcpx-6fm6-wx23 \u2014 npm axios@1.17.0",
        "description": "aliases: GHSA-hcpx-6fm6-wx23 | CVSS: 6.9",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-jqh4-m9w3-8hp9",
        "title": "GHSA-jqh4-m9w3-8hp9 \u2014 npm axios@1.17.0",
        "description": "aliases: GHSA-jqh4-m9w3-8hp9 | CVSS: 6.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-mmx7-hfxf-jppx",
        "title": "GHSA-mmx7-hfxf-jppx \u2014 npm axios@1.17.0",
        "description": "aliases: GHSA-mmx7-hfxf-jppx | CVSS: 6.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-mwf2-3pr3-8698",
        "title": "GHSA-mwf2-3pr3-8698 \u2014 npm axios@1.17.0",
        "description": "aliases: GHSA-mwf2-3pr3-8698 | CVSS: 6.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-pmv8-rq9r-6j72",
        "title": "GHSA-pmv8-rq9r-6j72 \u2014 npm axios@1.17.0",
        "description": "aliases: GHSA-pmv8-rq9r-6j72 | CVSS: 6.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-xj6q-8x83-jv6g",
        "title": "GHSA-xj6q-8x83-jv6g \u2014 npm axios@1.17.0",
        "description": "aliases: GHSA-xj6q-8x83-jv6g | CVSS: 6.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "low",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-v422-hmwv-36x6",
        "title": "GHSA-v422-hmwv-36x6 \u2014 npm body-parser@2.2.2",
        "description": "aliases: CVE-2026-12590, GHSA-v422-hmwv-36x6 | CVSS: 3.7",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-4c8g-83qw-93j6",
        "title": "GHSA-4c8g-83qw-93j6 \u2014 npm fast-uri@3.1.2",
        "description": "aliases: CVE-2026-13676, GHSA-4c8g-83qw-93j6 | CVSS: 7.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-v2hh-gcrm-f6hx",
        "title": "GHSA-v2hh-gcrm-f6hx \u2014 npm fast-uri@3.1.2",
        "description": "aliases: CVE-2026-16221, GHSA-v2hh-gcrm-f6hx | CVSS: 7.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-hmw2-7cc7-3qxx",
        "title": "GHSA-hmw2-7cc7-3qxx \u2014 npm form-data@4.0.5",
        "description": "aliases: CVE-2026-12143, GHSA-hmw2-7cc7-3qxx | CVSS: 8.7",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-hvrm-45r6-mjfj",
        "title": "GHSA-hvrm-45r6-mjfj \u2014 npm hono@4.12.25",
        "description": "aliases: CVE-2026-59896, GHSA-hvrm-45r6-mjfj | CVSS: 6.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-w62v-xxxg-mg59",
        "title": "GHSA-w62v-xxxg-mg59 \u2014 npm hono@4.12.25",
        "description": "aliases: CVE-2026-59895, GHSA-w62v-xxxg-mg59 | CVSS: 6.1",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-xgm2-5f3f-mvvc",
        "title": "GHSA-xgm2-5f3f-mvvc \u2014 npm hono@4.12.25",
        "description": "aliases: CVE-2026-59897, GHSA-xgm2-5f3f-mvvc | CVSS: 4.8",
        "remediation": null
      }
    ],
    "execution_duration_seconds": 17.684758159011835,
    "status": "complete",
    "examined": {
      "unit": "manifests",
      "count": 1
    },
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/google/osv-scanner/releases/tag/v2.3.8",
      "report_type": "osv-vulnerability",
      "ecosystems_seen": [
        "npm"
      ],
      "install_command": "curl -sfL -o /usr/local/bin/osv-scanner https://github.com/google/osv-scanner/releases/download/v2.3.8/osv-scanner_linux_amd64 && echo '<sha256>  /usr/local/bin/osv-scanner' | sha256sum -c - && chmod +x /usr/local/bin/osv-scanner",
      "severity_counts": {
        "low": 1,
        "high": 4,
        "medium": 13,
        "critical": 0,
        "informational": 0
      },
      "manifests_scanned": [
        "/repo/package-lock.json"
      ],
      "finding_id_aliases": {
        "GHSA-4c8g-83qw-93j6": [
          "CVE-2026-13676"
        ],
        "GHSA-hmw2-7cc7-3qxx": [
          "CVE-2026-12143"
        ],
        "GHSA-hvrm-45r6-mjfj": [
          "CVE-2026-59896"
        ],
        "GHSA-v2hh-gcrm-f6hx": [
          "CVE-2026-16221"
        ],
        "GHSA-v422-hmwv-36x6": [
          "CVE-2026-12590"
        ],
        "GHSA-w62v-xxxg-mg59": [
          "CVE-2026-59895"
        ],
        "GHSA-xgm2-5f3f-mvvc": [
          "CVE-2026-59897"
        ]
      },
      "cross_scanner_correlation": {
        "only_osv": [],
        "only_trivy": [],
        "intersection_ids": [
          "CVE-2026-12143",
          "CVE-2026-12590",
          "CVE-2026-13676",
          "CVE-2026-16221",
          "CVE-2026-59895",
          "CVE-2026-59896",
          "CVE-2026-59897",
          "GHSA-42h9-826w-cgv3",
          "GHSA-7q8q-rj6j-mhjq",
          "GHSA-f4gw-2p7v-4548",
          "GHSA-frvp-7c67-39w9",
          "GHSA-gcfj-64vw-6mp9",
          "GHSA-hcpx-6fm6-wx23",
          "GHSA-jqh4-m9w3-8hp9",
          "GHSA-mmx7-hfxf-jppx",
          "GHSA-mwf2-3pr3-8698",
          "GHSA-pmv8-rq9r-6j72",
          "GHSA-xj6q-8x83-jv6g"
        ]
      }
    },
    "display_score": 0.0,
    "display_badge": "Unsafe"
  }
]
```
