THRONE
See report Verify server

registry / record

@azure/mcp

npm / sealed 2026-06-13 / No. 53ab957e

> throne registry @azure/mcp sealed
This server needs launch argumentsthe server requires command-line arguments (for example a database URL) that a bare launch does not pass — Required command was not provided.
receiptsealed evidence
scan id
53ab957eb9b84d09ae4d251e9aaa67be
target
@azure/mcp
sealed at
2026-06-13 04:10:53Z
evidence hash
sha256:e849d18e4717e0ea31effa547a55e1c8cc5e9c296cf8546ab66b29099d9a2d5e
01connectFAIL0ms

server never launched: server process exited with code 1 before the MCP handshake — stderr: Required command was not provided.

02discoverSKIPPED0ms

not run — server never launched

03validate_schemasSKIPPED0ms

not run — server never launched

04smoke_test_toolsSKIPPED0ms

not run — server never launched

05error_handlingSKIPPED0ms

not run — server never launched

06streamingSKIPPED0ms

not run — server never launched

07resource_lifecycleSKIPPED0ms

not run — server never launched

08concurrent_callsSKIPPED0ms

not run — server never launched

09reconnectSKIPPED0ms

not run — server never launched

01connectFAIL0ms

server never launched: server process exited with code 1 before the MCP handshake — stderr: Required command was not provided.

02discoverSKIPPED0ms

not run — server never launched

03validate_schemasSKIPPED0ms

not run — server never launched

04smoke_test_toolsSKIPPED0ms

not run — server never launched

05error_handlingSKIPPED0ms

not run — server never launched

06streamingSKIPPED0ms

not run — server never launched

07resource_lifecycleSKIPPED0ms

not run — server never launched

08concurrent_callsSKIPPED0ms

not run — server never launched

09reconnectSKIPPED0ms

not run — server never launched

chatgpt desktopemulation profile pending real-traffic captureCOMING SOON
SECURITY: REVIEW / 4 finding(s), 1 high / review material, not a verdict
HIGHTHR-INSTALL-03 / Install-time script execution (npm lifecycle)

"postinstall" runs arbitrary code on every npm install: 'node ./scripts/post-install-script.js'

package/package.json
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

execSync() called with a dynamically built command (heuristic — review): '`npm install ${platformPackageName}@${packageVersion}`, {'

package/index.js:49
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

execSync() called with a dynamically built command (heuristic — review): '`npm install ${platformPackageName}@${packageVersion} --no-save --prefer-online`'

package/index.js:58
LOWTHR-NET-05 / Hardcoded outbound endpoints

1 non-local endpoint host(s) referenced in code — verify each is expected for this server's purpose: aka.ms (package/scripts/post-install-script.js:20)

package/scripts/post-install-script.js:20
VERDICT: NEEDS LAUNCH ARGUMENTSSANDBOXED RUN — submitted server executed in a disposable microVM — compatibility not assessable: needs arguments: the server requires command-line arguments (for example a database URL) that a bare launch does not pass — Required command was not provided. / security: review — 4 finding(s), 1 highsealed by THRONE / No. 53ab957e / 2026-06-13
executed in a disposable microVM, created for this scan and destroyed after it. nothing outlives a run.

maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.

this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.