D

@azure/mcp

npm · v3.0.0-beta.41 · 7 packages installed

Azure MCP Server - Model Context Protocol implementation for Azure

Installing this server brings 7 third-party packages inside your agent's trust boundary (0 direct). This is attack surface, not a vulnerability count — it does not affect the grade above.

▲ This count understates what you install — 7 of 7 packages are prebuilt binaries. Compiled binaries ship code you cannot read, so a low number here means less you can inspect, not less you are trusting.

1 package in this tree runs a script at install time.

Findings (2)

Embed this badge

MCP security grade D
[![MCP security](https://vulnrable.com/api/mcpbadge?pkg=%40azure%2Fmcp&eco=npm)](https://vulnrable.com/mcp/azure--mcp/)

Automated registry-metadata scan; not a code audit. Findings come from npm metadata published by the package owner and from public security advisories (OSV/GHSA) — not from our own assessment of the code.
Grade scanned 2026-09-04 · package count resolved 2026-08-18. A package fixed after that date will still show its earlier grade here.
Maintainer and think this is wrong or out of date? Get in touch — corrections are welcome.