PkgRadar

npm · registry.npmjs.org

@engramprotocol/mcp-server

Remote Payload: matched "curl "

Why PkgRadar flagged 0.10.10

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/templates/hooks/session_start_boot.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.10.10Review122026-06-09
0.10.9Review122026-06-08
0.10.8Review122026-06-04
0.10.7Review122026-06-02
0.10.6Review122026-05-29
0.10.5Review122026-05-26
0.10.4Review122026-05-26

Block this in CI

PkgRadar gates @engramprotocol/mcp-server (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @engramprotocol/[email protected]
@engramprotocol/mcp-server — npm security scan | PkgRadar