PkgRadar

Cargo · crates.io

vex-mcp

Llm Injection Payload: AI-agent-directed instruction adjacent to credential exfil — prompt-injection payload (Shai-Hulud / SANDWORM_MODE). imperative="Ignore previous instructions" target=".ssh/id_rsa"

Why PkgRadar flagged 0.1.5

SeveritySignalEvidence
highLlm Injection PayloadAI-agent-directed instruction adjacent to credential exfil — prompt-injection payload (Shai-Hulud / SANDWORM_MODE). imperative="Ignore previous instructions" target=".ssh/id_rsa" · vex-mcp-0.1.5/src/detect/poisoning.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.5High risk452026-06-20
0.1.4High risk452026-06-20
0.1.3High risk452026-06-20
0.1.2High risk452026-06-20
0.1.1High risk452026-06-20
0.2.1High risk602026-06-20
0.2.0High risk602026-06-20

Block this in CI

PkgRadar gates vex-mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]