Developer cache audit finds 264 vulnerable packages, AI agent tools hidden in unaudited npx cache
julsimon · x · 2026-09-27
The author released Cache Commander 0.4.3, adding support for Hugging Face's new cache format plus security fixes.
A full scan on his Mac turned up 71.7 GiB of developer caches, including 264 cached packages with known advisories. The new HF cache format stores each large file in one place and links it into every repo, which made his old build miss 1.5 GiB — model folders looked empty.
The worst offender was the npx cache: an MCP filesystem server dating to September 2025 carries 22 vulnerable dependencies, alongside 8 copies of chrome-devtools-mcp (1.0.1–1.6.0, latest 1.10.1). His point: your AI agent's tools live in a cache nobody audits. Install via brew install juliensimon/tap/ccmd on Mac/Linux.
Related event: Cache Commander 0.4.3 Uncovers Vulnerable Packages in Developer Caches(3 posts)→
More from Infra
- Three myths of hosted LLM inference: sticker prices, interchangeable endpoints, and self-hosting — TangeloOk9486 · 2026-09-27
- Random Attention: Salesforce and UIUC find random KV cache eviction rivals handcrafted signals — jiqizhixin · 2026-09-27
- Laptop engine streams a 35B model from SSD at 9.4 tok/s, beating GPT-OSS 20B — ImBadGuyInEveryStory · 2026-09-27
- World's fastest panel QR factorization on B200: how a GPU MODE contestant cracked chained dependencies — A_K_Nain · 2026-09-27
- TensorSharp open-source engine adds mixed document/image/video/audio inputs per request — fuzhongkai · 2026-09-27
- Pro-data center rally clashes with protesters as scholar defends AI infrastructure — neil_chilson · 2026-09-27