@azure/mcp
Azure MCP Server - Model Context Protocol implementation for Azure
5
Versions
MIT
License
Yes
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
azure-sdkmicrosoft1esmicrosoft-oss-releases
Keywords
azuremcpmodel-context-protocol
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@azure/mcp-linux-x64 | AI (dependencies): Platform-specific optional dependency for Linux x64 binary — standard cross-platform binary distribution pattern used by this Microsoft package. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require loads the platform-specific optional dependency by name — a well-known and safe pattern for platform binary dispatch. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process used only as fallback to auto-install missing optional platform package via npm — benign in context of binary wrapper pattern. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped @azure/mcp package from Microsoft; levenshtein match to 'yup' is a false positive with no brand impersonation intent. | ai | |
| phantom-deps | phantom-dep:@azure/mcp-linux-x64 | AI (phantom-deps): Platform-specific optional dep loaded by convention via dynamic require in postinstall — not a phantom dep in the malicious sense. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall selects the correct platform-specific binary package from optional deps — standard pattern for cross-platform binary wrappers (esbuild, turbo, etc.). | ai | |
| phantom-deps | phantom-dep:@azure/mcp-darwin-x64 | AI (phantom-deps): Platform-specific optional dep loaded by convention via dynamic require in postinstall — not a phantom dep in the malicious sense. | ai | |
| phantom-deps | phantom-dep:@azure/mcp-linux-arm64 | AI (phantom-deps): Platform-specific optional dep loaded by convention via dynamic require in postinstall — not a phantom dep in the malicious sense. | ai | |
| phantom-deps | phantom-dep:@azure/mcp-win32-arm64 | AI (phantom-deps): Platform-specific optional dep loaded by convention via dynamic require in postinstall — not a phantom dep in the malicious sense. | ai | |
| phantom-deps | phantom-dep:@azure/mcp-darwin-arm64 | AI (phantom-deps): Platform-specific optional dep loaded by convention via dynamic require in postinstall — not a phantom dep in the malicious sense. | ai | |
| phantom-deps | phantom-dep:@azure/mcp-win32-x64 | AI (phantom-deps): Platform-specific optional dep loaded by convention via dynamic require in postinstall — not a phantom dep in the malicious sense. | ai |