High / mcp_unpinned_package
MCP server "demo" runs a package executor without an obvious pinned package version.
Replace unversioned or @latest package references with a reviewed explicit version.
Evidence
command=npx args=-y @modelcontextprotocol/server-filesystem $HOME url=