Update Hijack Poc runs on your own machine — the client starts it, so there is no endpoint to ping. 19 installs a week from npm.
PoC benign MCP server for update-hijack security research
The linked repository no longer exists on GitHub — it was deleted or made private.
Quiet is not dead — but it is worth knowing when it wakes up, or when someone else takes it over. We watch the repository and tell you either way.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add update-hijack-poc -- npx -y @nottiboy1337/mcp-update-hijack-poc
{
"mcpServers": {
"update-hijack-poc": {
"args": [
"-y",
"@nottiboy1337/mcp-update-hijack-poc"
],
"command": "npx"
}
}
}
[mcp_servers.update-hijack-poc]
command = "npx"
args = ["-y", "@nottiboy1337/mcp-update-hijack-poc"]
{
"mcpServers": {
"update-hijack-poc": {
"args": [
"-y",
"@nottiboy1337/mcp-update-hijack-poc"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"update-hijack-poc": {
"args": [
"-y",
"@nottiboy1337/mcp-update-hijack-poc"
],
"command": "npx"
}
}
}
MCP server for Security
Security scanner and runtime proxy for MCP servers.
PoC: Open Registry supply chain — unvetted server listing (security research)
Trust verification for MCP servers. Check scores, scan for security issues, search 4,200+ servers.
Secure read-only MCP server for Slack workspaces
MCP server for web application security scanning
MCP server for running Ox Security MegaLinter via mega-linter-runner
Secure MCP server for MediaWiki wikis — search, pages, categories, and more
Answers built from our own checks of this server.