Skip to content

docs: point CLAUDE.md at common-thread-mcp - #264

Merged
Conrad Rockenhaus (skyphusion) merged 1 commit into
mainfrom
docs/claude-mcp-pointer
Aug 7, 2026
Merged

docs: point CLAUDE.md at common-thread-mcp#264
Conrad Rockenhaus (skyphusion) merged 1 commit into
mainfrom
docs/claude-mcp-pointer

Conversation

@skyphusion

Copy link
Copy Markdown
Member

Agent MCP door is the separate MIT package @skyphusion/common-thread-mcp (npm 0.1.1).

@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown

Adversarial security audit

Generated 2026-08-07T08:47:06.018Z · ce3a6fa...868bd91

New MCP agent door documentation adds a remote API-consuming package invoked via npx without mentioning authentication, pinning, or supply-chain controls.

Severity Location Finding
high CLAUDE.md:43 Unpinned npx MCP package: Documentation instructs npx -y @skyphusion/common-thread-mcp, which always pulls latest from npm. A compromised publish or namespace typo can execute arbitrary code inside crew tooling.
high CLAUDE.md:47 MCP server defaults to hosted backend: MCP points at COMMON_THREAD_API_URL defaulting to the hosted backend. If run without BYOK configuration, the MCP tool likely sends investigation data and AI secrets to the SaaS operator.
medium CLAUDE.md:43 MCP expands attack surface undocumented: Docs introduce a new stdio MCP server with website/API parity but do not mention authZ model, token scoping, or how it binds to existing investigation capability tokens.

@skyphusion
Conrad Rockenhaus (skyphusion) merged commit 54708c5 into main Aug 7, 2026
10 of 11 checks passed
@skyphusion
Conrad Rockenhaus (skyphusion) deleted the docs/claude-mcp-pointer branch August 7, 2026 08:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant