#16 fixed the CVE, but we don't have a release, so it shows up during npm audit:
❯ npm audit
# npm audit report
@wong2/mcp-cli *
wong2 mcp-cli Command Injection Vulnerability - https://github.com/advisories/GHSA-p6rm-483j-37jf
No fix available
node_modules/mcp-cli
1 low severity vulnerability
Some issues need review, and may require choosing
a different dependency.