Dev caches hide 264 CVE-laden packages and 71.7 GiB no one audits, warns Cache Commander dev

julsimon · x · 2026-09-27

The author released Cache Commander 0.4.3, adding support for HuggingFace's new cache format plus security fixes, and ran a full scan on his own Mac.

Key findings:

The core point: your AI agent's tools (MCP servers) live in cache directories nobody audits — a neglected supply-chain attack surface. ccmd is a TUI + MCP server that scans pip/npm/Cargo/HuggingFace/Homebrew caches for CVEs, flags outdated packages, and reclaims disk space.

Related event: Cache Commander 0.4.3 Uncovers Vulnerable Packages in Developer Caches(3 posts)→

Original post →

More from coding & agent

coding & agent channel →