ai.etincel/etincel-nonfiction
findings 阈值 medium · 生成于 2026-09-16T11:52:30.103Z
包:etincel@0.10.1 (npm)
仓库:https://github.com/AIStoryHub/etincel
这份记录是怎么来的
两样都是公开的:注册表里的条目,以及这个包在 npm 上实际发布的清单。下面是每一条发现,带它在哪个文件、属于哪条规则。
发现是"形状",不是"结论"。规则匹配的是代码与配置里的形状;一条 medium 不表示有人能利用它,也不表示我们知道对方是怎么用的。低于阈值的项不会改变结论。没测到的部分单列在下面——没测到不等于干净。
registryDocument
status=findings · source=mcp-census
| 规则 | 级别 | 位置 | 说明 |
|---|---|---|---|
| stdio-transport | info | packages[].transport.type=stdio (runs locally as a child process) | |
| install-time-execution | high | scripts.postinstall="node -e \"require('fs').existsSync('tsconfig.json')&&require('child_process').execSync('npm run build',{stdio:'inherit'})\"" |
packageManifest
status=findings · source=guard-scan
| 规则 | 级别 | 位置 | 说明 |
|---|---|---|---|
| AG-INSTALL-001 | medium | package.json | the postinstall script evaluates inline code at install time (the inline code runs a command at install time, but the command is a fixed literal, so nothing here can redirect it) |
没测到的部分
这条记录里没有 unmeasured 的块。
机器可读
同一条记录的 JSON:https://app.xn--5kvo87g.com/v1/servers/ai.etincel%2Fetincel-nonfiction
徽章(可直接放进 README):https://app.xn--5kvo87g.com/badge/ai.etincel%2Fetincel-nonfiction.svg