← 证据索引

ai.buywhere/buywhere-mcp

findings 阈值 medium · 生成于 2026-09-16T11:52:30.103Z

包:@buywhere/mcp-server@0.3.1 (npm)
仓库:https://github.com/BuyWhere/buywhere-mcp

这份记录是怎么来的

两样都是公开的:注册表里的条目,以及这个包在 npm 上实际发布的清单。下面是每一条发现,带它在哪个文件、属于哪条规则。

发现是"形状",不是"结论"。规则匹配的是代码与配置里的形状;一条 medium 不表示有人能利用它,也不表示我们知道对方是怎么用的。低于阈值的项不会改变结论。没测到的部分单列在下面——没测到不等于干净。

registryDocument

status=findings · source=mcp-census

规则级别位置说明
stdio-transportinfopackages[].transport.type=stdio (runs locally as a child process)
install-time-executioninfoscripts.postinstall="node -e \"try{require('fs').existsSync(require('path').join(__dirname,'dist','index.js'))&&console.log('\\n ✦ BuyWhere MCP server v0.3.0 installed\\n › Set BUYWHERE_API_KEY and add to your MCP client config\\n › Docs: https://github.com/BuyWhere/buywhere/tree/main/packages/mcp-server\\n')}catch(e){}\"" (evaluates inline code that only prints)
repository-mismatchmediumpackage repository github.com/buywhere/buywhere vs registry repository github.com/buywhere/buywhere-mcp
declared-version-not-latestinforegistry declares 0.3.1, npm latest is 0.4.0

packageManifest

status=clean · source=guard-scan

这一块没有产生发现。

没测到的部分

这条记录里没有 unmeasured 的块。

机器可读

同一条记录的 JSON:
https://app.xn--5kvo87g.com/v1/servers/ai.buywhere%2Fbuywhere-mcp

徽章(可直接放进 README):
https://app.xn--5kvo87g.com/badge/ai.buywhere%2Fbuywhere-mcp.svg