← Back to search Server uses network capabilities via: fetch() Server uses shell capabilities via: spawn() Server uses env_vars capabilities via: process.env
@exfil/canary
Transparent MCP proxy that watermarks agent tool responses and blocks data exfiltration caused by prompt injection.
? Not scanned yet
Versions
1.0.0latestMar 21, 2026
Tools 0
No tools indexed yet.
Permissions 3
network medium shell high env_vars low Scan Findings 15
high
Hardcoded API key in exfil-hq-Canary-b787977/src/__tests__/entities.test.ts
medium
OAuth implementation without PKCE
info
Sandbox failed to start for behavioral verification
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.0.0 (GHSA-w48q-cv73-mx4w)
medium
Vulnerable dependency: vitest@2.1.9 (GHSA-5xrq-8626-4rwp)
medium
Vulnerable dependency: vitest@2.1.9 (GHSA-82fw-gwwq-j7x9)
info
package.json metadata
info
Transport: stdio
info
Required env vars (8)
info
Sandbox failed to start for output poisoning scan
medium
Permission: network access detected
high
Permission: shell access detected
low
Permission: env_vars access detected
info
SBOM generated: 4 components
medium
No build provenance detected (SLSA L0)