Go modules · proxy.golang.org
github.com/gnoverse/gno-mcp
Shell Credential File Read, Remote Payload
Why PkgRadar flagged v0.2.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Shell Credential File Read | github.com/gnoverse/[email protected]/internal/keystore/keystore.go |
| medium | Remote Payload | github.com/gnoverse/[email protected]/cmd/agentfaucet/main.go |
| medium | Remote Payload | github.com/gnoverse/[email protected]/cmd/gnomcp/main.go |
| medium | Remote Payload | github.com/gnoverse/[email protected]/internal/profiles/config.go |
| medium | Remote Payload | github.com/gnoverse/[email protected]/internal/profiles/discovery.go |
| medium | Remote Payload | github.com/gnoverse/[email protected]/internal/tools/read/budgeted.go |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v0.2.0 | High risk | 69 | 2026-06-23 |
v0.7.1-0.20260622104221-00f82b116c49 | High risk | 69 | 2026-06-23 |
Block this in CI
pkgradar gate --ecosystem go github.com/gnoverse/[email protected]