ruvnet / ruvnet/agentic-flow

MCP security scan: agentic-flow (score 60/100)

Open
#142 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
812
Forks
175
Avg merge
2m
Merged PRs (30d)
3

Description

We ran a security scan on agentic-flow@2.0.7 as part of our MCP ecosystem monitoring.

Score: 60/100
Risk: ELEVATED

Findings
  • [MEDIUM] excessive dependencies: Package has 25 runtime dependencies (high attack surface)
  • [HIGH] command injection: Potential command injection: shell execution with template literal input
What this checks

Install scripts, prompt injection patterns in metadata, suspicious URLs, source code patterns (command injection, unsafe eval, hardcoded secrets), dependency count, metadata completeness, and publisher provenance.

How to verify

You can scan this package yourself at https://agentscores.xyz/scan or via the API:

curl "https://agentscores.xyz/api/scan?npm=agentic-flow"

This is an automated scan. If any finding is incorrect, we'd appreciate knowing so we can improve detection accuracy.

Full written reviews with hardening recommendations: https://agentscores.xyz/security-review


Scanned by AgentScore MCP security monitoring.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the AgentScore scan for agentic-flow@2.0.7 using the linked API or scan site, then trace the reported shell execution with template-literal input in the package source. Verify whether the command-injection finding and elevated risk are accurate, and document the result or a narrowly scoped remediation; no source file or test is identified in the issue.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.