npm · registry.npmjs.org
@amazon-sp-api-release/sp-api-dev-mcp
Shipped Live Secret, Large Javascript Payload
Why PkgRadar flagged 1.0.1
| Severity | Signal | Evidence |
|---|---|---|
| high | Shipped Live Secret | package/bundled-servers/models/services-api-model/services.json |
| high | Shipped Live Secret | package/bundled-servers/models/uploads-api-model/uploads_2020-11-01.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.0.1 | High risk | 50 | 2026-06-24 |
1.0.2 | High risk | 50 | 2026-06-24 |
1.0.3 | High risk | 50 | 2026-06-24 |
1.0.4 | High risk | 50 | 2026-06-24 |
Block this in CI
pkgradar gate --ecosystem npm @amazon-sp-api-release/[email protected]