AI tool official ai-agent
Risk level
low
10/100

Globally-installed MCP servers (npm)

Globally-installed MCP servers (npm) is an officially published AI tool from npm. Anomity scores its risk at 10 out of 100 (low).

Analysis summary

Globally-installed MCP servers (npm) is an officially published AI tool from npm. Anomity scores its risk at 10 out of 100 (low).

Official @modelcontextprotocol/server-* packages installed via `npm install -g`. Available to any agent on the system; the daemon surfaces them so they get classified and policy-evaluated like configured MCPs.

Why this entry scored 10 out of 100

This profile starts at the catalog's neutral base of 50. Because the entry is officially published, trust adjusts the score by -40. The entry declares no high-risk capabilities on its own, so capabilities add nothing. It matches no dangerous capability combinations. The clamped result is 10, placing it in the low band.

See the full scoring formula →

Findings

  • Published by the vendor Trust offset
    Contribution to score: -40

Configuration surface

Files this AI tool reads on the host. Anything written here changes what the agent does next.

  • global-mcp-npm-modelcontextprotocol-win-default global json
    @modelcontextprotocol/server-* (Windows default %APPDATA%\npm prefix)
  • global-mcp-npm-modelcontextprotocol-unix-system global json
    @modelcontextprotocol/server-* (system-wide /usr/local on macOS/Linux)
  • global-mcp-npm-modelcontextprotocol-unix-userprefix global json
    @modelcontextprotocol/server-* (user-prefix ~/.npm-global)