A TypeScript SSE proxy for MCP servers that use stdio transport.
92%
Total Score
100
100
94
67
100
The project uses TypeScript and npm scripts for builds, but no security scanning tools were detected. This is a modest hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
Both workflows were analyzed without injection or high-severity findings, and one scopes permissions at job level. However, all six action references are unpinned, creating a moderate reproducibility and action-supply-chain hygiene gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-665211 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. mcp-proxy is vulnerable to Denial of Service (DoS) in versions 3.0.0 - 6.5.1. | 3.0.0 - 6.5.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
pipenet Version ^1.3.0 | — | — |
@modelcontextprotocol/client Version ^2.0.0 | — | — |
@modelcontextprotocol/server Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.