@hhxhhxhhx/hhx-mcp-audit

ISCLicense declared in the package manifest.

一个用于**前端工程依赖安全审计**的 MCP Server:在 Cursor 里调用 `auditPackage` 工具,即可对指定项目(本地路径或 GitHub 仓库)做依赖漏洞审计,并输出一份可直接阅读/分享的 Markdown 报告。

100

Security score

0 known advisories in v1.1.0

0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.advisory penalty −0 · staleness penalty −0

Weekly downloads

Downloads across all versions in the last 7 days, from the official npm downloads API (api.npmjs.org).

Unpacked size

Size of v1.1.0 on disk after npm install extracts the tarball, as reported by the npm registry.

22.2 kB

Dependencies

Direct runtime dependencies declared by v1.1.0. Transitive dependencies are not counted here — use the lockfile audit for the full tree.

3

Last publish

When v1.1.0 was published to the registry. Long gaps can indicate an unmaintained package.

7 months ago

Security advisories

Vulnerabilities affecting v1.1.0 specifically, from OSV.dev — the open database aggregating the GitHub Advisory Database (GHSA) and CVEs. Links open the full advisory.

No known vulnerabilities affect v1.1.0.