Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 months ago
- Version
- v0.2.0
- Artifact
- SHA256 459…D11
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Tool Poisoning Assessment: Zero tool-poisoning findings exist in this package. The findings summary explicitly shows "tool-poisoning":"0". There are no hidden AI directives, no XML-style instruction tags, and no Unicode steganography in tool descriptions. This is a critical finding—without tool poisoning, the defining MCP threat is absent.
Credential and Network Access: The IoC findings reference only legitimate Groq API endpoints: XIOC-URL-https://api.groq.com/openai/v1 and XIOC-URL-https://console.groq.com/keys. These match the package's stated purpose of Groq Speech-to-Text transcription. No credential-access findings target sensitive paths like .ssh/, .aws/, .kube/, or specific secret names like GITHUB_TOKEN or AWS_SECRET_ACCESS_KEY. There are zero network findings showing exfiltration to unknown domains. The findings_summary shows "network":"0" and "secret":"0".
False Positive Drivers: The 16 IoC findings are documentation artifacts, not executable code. Examples include placeholder URLs like XIOC-URL-https://github.com/[seu-usuario]/n8n-nodes-groq.git (Portuguese "seu-usuario" = "your user"), example domains like XIOC-DOMAIN-exemplo.com, and JavaScript property access misread as domains: XIOC-DOMAIN-date.now and XIOC-DOMAIN-this.properties. The W3C namespace XIOC-URL-http://www.w3.org/2000/svg is standard XML, not a network call. The 9 code-smell findings are low-severity YARA matches on generic patterns.
Strongest Counterargument: The developer "marcos345" is anonymous and the package has zero users. However, this is a new community node (version 0.2.0) where the absence of users may simply reflect recency. The technical evidence—zero tool poisoning, zero credential theft, zero exfiltration domains—overrides the publisher anonymity concern. The code's behavior matches its documented purpose: calling the Groq API for speech-to-text.
Conclusion: This package exhibits no malicious patterns. All findings stem from documentation strings, placeholder content, and code-smell false positives. The package performs its stated function without hidden behavior.
Key Reasons
- Zero tool-poisoning findings
- Zero credential-access findings targeting sensitive paths
- All IoC findings are documentation placeholders or false positives
- Network destinations match stated Groq API purpose
- Zero malware-signature findings
False Positive Considerations
- Documentation placeholder URLs (exemplo.com, [seu-usuario])
- JavaScript property access misread as domains (date.now, this.properties)
- W3C namespace URLs (www.w3.org, 2000/svg)
- Code-smell YARA matches on generic patterns
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace