PkgRadar

Cargo · crates.io

mcp-gateway

Remote Payload: matched "api.github.com/graphql"

Why PkgRadar flagged 2.19.0

SeveritySignalEvidence
mediumRemote Payloadmatched "api.github.com/graphql" · mcp-gateway-2.19.0/src/capability/definition/tests.rs
mediumRemote Payloadmatched "api.github.com/graphql" · mcp-gateway-2.19.0/src/capability/executor/graphql.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · mcp-gateway-2.19.0/src/registry/mod.rs
mediumRemote Payloadmatched "curl " · mcp-gateway-2.19.0/src/security/firewall/input_scanner.rs
mediumRemote Payloadmatched "curl " · mcp-gateway-2.19.0/src/security/response_inspect.rs
mediumRemote Payloadmatched "curl " · mcp-gateway-2.19.0/src/security/response_scanner.rs
mediumRemote Payloadmatched "curl " · mcp-gateway-2.19.0/src/tunnel.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
2.19.0High risk1142026-06-08
2.18.0High risk1142026-06-08
2.17.0High risk1142026-06-08
2.16.0High risk1142026-06-08
2.15.1High risk1142026-06-08
2.15.0High risk1142026-06-08
2.14.0High risk1142026-06-08
2.13.0High risk1142026-06-08
2.12.2High risk1142026-06-08

Block this in CI

PkgRadar gates mcp-gateway (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]