ICUICU
critical

mcp-server

v0.0.9

mcp server

npmmelvincarvalhoFirst seen Feb 22, 2026

2

Total

1

Critical

0

High

1

Medium

Findings

unknown
criticalDE-002Data ExfiltrationHigh ConfidenceLine 0

Environment file access

Detected by automated pattern matching (rule DE-002) with medium confidence. May be a false positive.

    141: 
    142: // Listen on port 4333.
>>> 143: const PORT = process.env.PORT || 4333;
    144: app.listen(PORT, '0.0.0.0', () => {
    145:   console.log(`Server listening on port ${PORT}`);
Report false positive
mediumEN-001unknownMedium ConfidenceLine 0

High-entropy string (4.7 bits/char) — possible encoded payload

Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.

Report false positive

Scan History

DateRiskFindings
Feb 25, 2026critical2
Feb 23, 2026critical2
Feb 22, 2026critical2