MCP Security Kit by Agent Trust Cloud

low

MCP server installs without asking (npx -y)

npx -y installs a package without a confirmation prompt, and the package isn't pinned.

Why it matters

A changed or typo-squatted package name runs silently.

How to fix it

Keep -y only together with an exact pinned version.

Before

{
  "mcpServers": {
    "memory": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-memory"
      ]
    }
  }
}

After

{
  "mcpServers": {
    "memory": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/[email protected]"
      ]
    }
  }
}

Illustrative configs. The checker flags the “before” version with this finding and not the “after” version.

Check your own config

Other checks