← Back to search Server uses shell capabilities via: child_process, execSync(), spawn(), spawnSync() Server uses env_vars capabilities via: process.env
MCP stdio ShellGuard
Defense-in-depth bundle for MCP stdio servers: drop-in guard for child_process.exec/spawn, AST audit CLI for unsanitized shell calls, and a reference MCP server that exposes both. Closes the Ox-Security 200k-server stdio-RCE class.
? Not scanned yet
Versions
0.1.2latestJun 21, 2026
0.1.1May 29, 2026
0.1.0May 7, 2026
Tools 0
No tools indexed yet.
Permissions 2
shell high env_vars low Scan Findings 10
info
Sandbox failed to start for behavioral verification
medium
Vulnerable dependency: vitest@2.1.0 (GHSA-5xrq-8626-4rwp)
medium
Vulnerable dependency: vitest@2.1.0 (GHSA-9crc-q9x8-hgqq)
info
package.json metadata
info
Transport: stdio
info
Sandbox failed to start for output poisoning scan
high
Permission: shell access detected
low
Permission: env_vars access detected
info
SBOM generated: 456 components
medium
No build provenance detected (SLSA L0)