PyPI · pypi.org
mcp-audit-scanner
Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution
Why PkgRadar flagged 0.12.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · mcp_audit_scanner-0.12.0/src/mcp_audit/analyzers/supply_chain.py |
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · mcp_audit_scanner-0.12.0/src/mcp_audit/analyzers/transport.py |
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · mcp_audit_scanner-0.12.0/src/mcp_audit/cli/shadow.py |
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · mcp_audit_scanner-0.12.0/src/mcp_audit/fixer/strategies/pinning.py |
| high | Webhook Exfil Endpoint | matched "pipedream.net" · mcp_audit_scanner-0.12.0/src/mcp_audit/registration/client.py |
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · mcp_audit_scanner-0.12.0/src/mcp_audit/registry/loader.py |
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · mcp_audit_scanner-0.12.0/src/mcp_audit/shadow/allowlist.py |
| high | Python Bun Js Exec | Python file references the Bun JavaScript runtime — cross-language execution · mcp_audit_scanner-0.12.0/src/mcp_audit/vulnerability/resolver.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.12.0 | High risk | 100 | 2026-06-13 |
0.11.0 | High risk | 50 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem pypi mcp-audit-scanner==0.12.0