Skip to content

Security scan results for typescript-sdk β€” MCPSafe AIVSS 53/100 (Grade F)Β #2078

@mcpsafe-gh

Description

@mcpsafe-gh

Hi team πŸ‘‹

I ran a free deep security scan of modelcontextprotocol/typescript-sdk using MCPSafe β€” a purpose-built scanner for MCP servers using a 5-LLM consensus panel to detect prompt injection risks, over-scoped tool schemas, supply chain issues, and more.

Results: 53/100 Β· Grade F

Severity Count
πŸ”΄ Critical 0
🟠 High 11
🟑 Medium 125
🟒 Low 0

Summary: 11 high + 125 medium findings across the SDK β€” worth reviewing before downstream MCP servers adopt these patterns

πŸ“‹ Full report with findings and evidence: https://mcpsafe.io/registry/github/modelcontextprotocol/typescript-sdk


Add a security badge to your README

[![MCPSafe](https://api.mcpsafe.io/badge/github/modelcontextprotocol/typescript-sdk.svg)](https://mcpsafe.io/registry/github/modelcontextprotocol/typescript-sdk)

This badge auto-updates whenever a new scan runs β€” great for showing users and enterprise customers your security posture at a glance.


Feel free to close this if you're already tracking these findings. Happy to answer any questions about specific findings.

β€” Truong BUI Β· mcpsafe.io

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions