I noticed the committed .mcp.json currently has three mutable npm/npx references:
chrome-devtools-mcp@latest
- bare
@primeng/mcp
- bare
@angular/cli
This is not a claim that any of these packages are malicious or vulnerable. The issue is reproducibility/review drift: the config can stay unchanged while a later npx resolution selects different package code than the version originally reviewed.
A simple control would be to pin each external MCP package to an exact reviewed version and update those pins intentionally.
I verified this with a passive static check only; no MCP server was executed and no package was downloaded. Author disclosure: I maintain the small open-source checker I used for this class of config drift: https://github.com/tomelias10/mcp-drift-check
Happy to provide the exact scanner output if useful.
I noticed the committed
.mcp.jsoncurrently has three mutable npm/npx references:chrome-devtools-mcp@latest@primeng/mcp@angular/cliThis is not a claim that any of these packages are malicious or vulnerable. The issue is reproducibility/review drift: the config can stay unchanged while a later
npxresolution selects different package code than the version originally reviewed.A simple control would be to pin each external MCP package to an exact reviewed version and update those pins intentionally.
I verified this with a passive static check only; no MCP server was executed and no package was downloaded. Author disclosure: I maintain the small open-source checker I used for this class of config drift: https://github.com/tomelias10/mcp-drift-check
Happy to provide the exact scanner output if useful.