The committed .mcp.json currently includes mutable package references including:
@upstash/context7-mcp@latest
@playwright/mcp@latest
- bare
@modelcontextprotocol/server-sequential-thinking
This is not a vulnerability report. It is a reproducibility/review-boundary issue: an unchanged MCP config can resolve to newer package code later. For teams that review MCP tooling before use, that makes the reviewed artifact non-deterministic.
Suggested control: pin external npm/npx MCP packages to reviewed exact versions and bump them deliberately.
I checked the config statically only; no servers were started and no packages were downloaded. Author disclosure: the passive checker used was https://github.com/tomelias10/mcp-drift-check.
The committed
.mcp.jsoncurrently includes mutable package references including:@upstash/context7-mcp@latest@playwright/mcp@latest@modelcontextprotocol/server-sequential-thinkingThis is not a vulnerability report. It is a reproducibility/review-boundary issue: an unchanged MCP config can resolve to newer package code later. For teams that review MCP tooling before use, that makes the reviewed artifact non-deterministic.
Suggested control: pin external npm/npx MCP packages to reviewed exact versions and bump them deliberately.
I checked the config statically only; no servers were started and no packages were downloaded. Author disclosure: the passive checker used was https://github.com/tomelias10/mcp-drift-check.