PkgRadar

npm · registry.npmjs.org

agent-security-scanner-mcp

Webhook Exfil Endpoint: matched "webhook.site"

Why PkgRadar flagged 4.4.0

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "webhook.site" · package/src/tools/scan-action.js

Scanned versions

VersionVerdictScoreScanned (UTC)
4.4.0High risk752026-06-10
4.4.3High risk752026-06-10
4.4.1High risk752026-06-10
4.4.2High risk752026-06-10

Block this in CI

PkgRadar gates agent-security-scanner-mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]