Most [MCP servers](https://github.com/modelcontextprotocol/servers) suggest using `npx -y` as the recommended way to install a server. This downloads and executes arbitrary scripts from the internet. This is grossly insecure and I think the MCP authors sh
Most [MCP servers](https://github.com/modelcontextprotocol/servers) suggest using `npx -y` as the recommended way to install a server. This downloads and executes arbitrary scripts from the internet. This is grossly insecure and I think the MCP authors sh
Is it safe?
No known CVEs for @considered/harmful.
No authentication — any process on your machine can connect to this server.
License not specified.
Last scanned 0 days ago.
Is it maintained?
Commit history unknown.
Will it work with my client?
Transport: stdio. Works with Claude Desktop, Cursor, Claude Code, and most MCP clients.
How much context will it use?
0 tools. Token cost not measured.
What if it doesn't work?
Common issues: JSON syntax errors in config, wrong Node.js version, npx cache. covers troubleshooting.
{
"mcpServers": {
"harmful": {
"command": "npx",
"args": [
"-y",
"@considered/harmful"
]
}
}
}Auto-generated from package name. Add to your client's MCP config file.
Run this in your terminal to verify the server starts. Then let us know if it worked — your result helps other developers.
npx -y @considered/harmful 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
This server is missing description, tools, and install config. If you've used it, help the community by adding this info.
Add informationLast scanned 6h ago
No known vulnerabilities.
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.