{"id":"4e198520-9503-4c1b-b4d6-105a8d2338af","slug":"npm-considered-harmful","name":"@considered/harmful","description":"Most [MCP servers](https://github.com/modelcontextprotocol/servers) suggest using `npx -y` as the recommended way to install a server. This downloads and executes arbitrary scripts from the internet. This is grossly insecure and I think the MCP authors sh","canonicalUrl":"https://www.xpersona.co/skill/npm-considered-harmful","sourceUrl":"https://www.npmjs.com/package/@considered/harmful","homepage":null,"source":"NPM","vendor":{"slug":"npmjs","label":"Npmjs","url":"https://www.npmjs.com/package/@considered/harmful"},"protocols":["MCP","OPENCLEW"],"capabilities":[],"trustScore":null,"trustConfidence":"unknown","artifactCount":0,"benchmarkCount":0,"lastRelease":"1.0.3","freshnessAt":"2026-02-23T19:13:17.612Z","freshnessLabel":"Feb 23, 2026","securityReviewed":true,"openapiReady":true,"stats":[{"label":"Trust score","value":"Unknown"},{"label":"Compatibility","value":"MCP, OpenClaw"},{"label":"Freshness","value":"Feb 23, 2026"},{"label":"Vendor","value":"Npmjs"},{"label":"Artifacts","value":"0"},{"label":"Benchmarks","value":"0"},{"label":"Last release","value":"1.0.3"}],"factsPreview":[{"factKey":"protocols","category":"compatibility","label":"Protocol compatibility","value":"MCP, OpenClaw","href":"https://www.xpersona.co/api/v1/agents/npm-considered-harmful/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/npm-considered-harmful/contract","sourceType":"contract","confidence":"high","observedAt":"2026-02-24T19:58:45.464Z","isPublic":true},{"factKey":"auth_modes","category":"compatibility","label":"Auth modes","value":"mcp","href":"https://www.xpersona.co/api/v1/agents/npm-considered-harmful/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/npm-considered-harmful/contract","sourceType":"contract","confidence":"high","observedAt":"2026-02-24T19:58:45.464Z","isPublic":true},{"factKey":"schema_refs","category":"artifact","label":"Machine-readable schemas","value":"OpenAPI or schema references published","href":"https://www.npmjs.com/package/@considered/harmful#input","sourceUrl":"https://www.xpersona.co/api/v1/agents/npm-considered-harmful/contract","sourceType":"contract","confidence":"high","observedAt":"2026-02-24T19:58:45.464Z","isPublic":true},{"factKey":"vendor","category":"vendor","label":"Vendor","value":"Npmjs","href":"https://www.npmjs.com/package/@considered/harmful","sourceUrl":"https://www.npmjs.com/package/@considered/harmful","sourceType":"profile","confidence":"medium","observedAt":"2026-02-24T19:43:14.176Z","isPublic":true},{"factKey":"handshake_status","category":"security","label":"Handshake status","value":"UNKNOWN","href":"https://www.xpersona.co/api/v1/agents/npm-considered-harmful/trust","sourceUrl":"https://www.xpersona.co/api/v1/agents/npm-considered-harmful/trust","sourceType":"trust","confidence":"medium","observedAt":null,"isPublic":true}],"highlights":["Schema refs published","Trust evidence available"],"agentCard":{"name":"@considered/harmful","description":"Most [MCP servers](https://github.com/modelcontextprotocol/servers) suggest using `npx -y` as the recommended way to install a server. This downloads and executes arbitrary scripts from the internet. This is grossly insecure and I think the MCP authors sh","source":"NPM","sourceId":"npm:@considered/harmful","repository":"https://www.npmjs.com/package/@considered/harmful","documentation":"https://www.xpersona.co/skill/npm-considered-harmful/agent/npm-considered-harmful","protocols":["MCP","OPENCLEW"],"languages":["typescript"],"install":{"command":"npm install @considered/harmful","ecosystem":"npm"}}}