中文 · English

← 证据索引

ai.flowdot/mcp-server

clean 阈值 medium · 生成于 2026-10-04T20:17:44.566Z

发布方:flowdot-llc

包:@flowdot.ai/mcp-server@1.3.21 (npm)
仓库:https://github.com/flowdot-llc/mcp-server

这份记录是怎么来的

两样都是公开的:注册表里的条目,以及这个包在 npm 上实际发布的清单。下面是每一条发现,带它在哪个文件、属于哪条规则。

仓库源码不在这份索引的扫描范围内——要查源码,用 CLI 在自己的机器上跑,代码不用给任何人。

发现是"形状",不是"结论"。规则匹配的是代码与配置里的形状;一条 medium 不表示有人能利用它,也不表示我们知道对方是怎么用的。低于阈值的项不会改变结论。没测到的部分单列在下面——没测到不等于干净。

registryDocument

status=findings · source=mcp-census

规则级别位置说明
stdio-transportinfopackages[].transport.type=stdio (runs locally as a child process)

packageManifest

status=findings · source=guard-scan

规则级别位置说明
AG-SUPPLY-001lowpackage.jsondevDependencies entry @flowdot.ai/api resolves to a path inside this repository, which nobody installing the published package can resolve: file:../flowdot-api (dev-only: cannot reach a consumer of this package)
AG-SUPPLY-001lowpackage.jsondevDependencies entry @flowdot.ai/documents resolves to a path inside this repository, which nobody installing the published package can resolve: file:../flowdot-documents (dev-only: cannot reach a consumer of this package)
AG-SUPPLY-001lowpackage.jsondevDependencies entry @flowdot.ai/cli-qa-engine resolves to a path inside this repository, which nobody installing the published package can resolve: file:../flowdot-cli-qa-engine (dev-only: cannot reach a consumer of this package)
AG-SUPPLY-001lowpackage.jsondevDependencies entry @flowdot.ai/browser-driver resolves to a path inside this repository, which nobody installing the published package can resolve: file:../flowdot-browser-driver (dev-only: cannot reach a consumer of this package)
AG-SUPPLY-001lowpackage.jsondevDependencies entry @flowdot.ai/platform-learn resolves to a path inside this repository, which nobody installing the published package can resolve: file:../flowdot-platform-learn (dev-only: cannot reach a consumer of this package)

没测到的部分

这条记录里没有 unmeasured 的块。

哪些扫描器跑完了

状态:complete · 必需 2 个,跑完 2 个,没跑成 0 个

扫描器是否必需状态输出一致性原因
registryDocument必需completed有 / 可读ok
packageManifest必需completed有 / 可读ok

机器可读

同一条记录的 JSON:
https://xn--5kvo87g.com/v1/servers/ai.flowdot%2Fmcp-server

徽章(可直接放进 README):
https://xn--5kvo87g.com/badge/ai.flowdot%2Fmcp-server.svg