The **Model Context Protocol (MCP) client** for the [AI SDK](https://ai-sdk.dev/docs) lets you connect to MCP servers and use their tools with AI SDK functions like `generateText` and `streamText`.
93%
Total Score
65
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10997 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @ai-sdk/mcp is vulnerable to Cross-Site Request Forgery (CSRF) in versions 1.0.0 - 1.0.27. | 1.0.0 - 1.0.27 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
pkce-challenge Version ^5.0.0 | — | — |
@ai-sdk/provider Version 3.0.10 | — | — |
@ai-sdk/provider-utils Version 4.0.27 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant