Based on the RiskyPlugins AI security review of the observed evidence.
No individual score drivers were recorded for this analysis.
Analysis record
- Analysed
- 5 months ago
- Version
- v1.0.9
- Artifact
- SHA256 498…94F
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Finding Categories
MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Tool Poisoning Assessment
No tool-poisoning findings were detected in this package. The findings summary shows "tool-poisoning":"0", meaning the scanner found zero instances of hidden AI directives, embedded instructions, or manipulation patterns in tool descriptions. This is a critical negative finding that rules out the defining MCP threat.
Credential and Network Access
The package has zero credential-access findings and zero network findings. The findings summary confirms "secret":"0" and "network":"0". There is no evidence of credential harvesting targeting sensitive paths like .ssh/, .aws/, .kube/config, or specific secret names like GITHUB_TOKEN or AWS_SECRET_ACCESS_KEY. The absence of actual network findings (distinct from XIOC noise) indicates no exfiltration architecture.
IoC False Positives
All six IoC findings are XIOC-DOMAIN false positives from property access chains misread as domains:
XIOC-DOMAIN-date.now- JavaScript method call, not a domainXIOC-DOMAIN-task.id- Object property access, not a domainXIOC-DOMAIN-task.result.total- Nested property access, not a domainXIOC-DOMAIN-images.map- Array method call, not a domainXIOC-DOMAIN-img.name- Property access, not a domainXIOC-DOMAIN-info.name- Property access, not a domain
Per the CVEQ false-positive documentation, property access chains like b.call, h.next, g.id are well-documented noise sources. These findings match that exact pattern.
Code-Smell Findings
All nine code-smell findings are YARA postinstall rules (postinstall_file_manipulation, postinstall_network_communication, postinstall_system_command) with severity: low in package.json, index.mjs, and README.md. Per the guidelines, these rules "fire on almost any non-trivial JavaScript" and "should NEVER drive a verdict." They match basic Node.js patterns like fetch, exec, fs, and process.env reads.
Strongest Counterargument
The anonymous publisher (one-yutian) and zero user count could suggest an unvetted package. However, these factors alone do not constitute evidence of malicious behavior. The package description ("remove image background and crop size") aligns with legitimate image processing functionality. Without tool poisoning, credential theft, or actual network exfiltration, publisher anonymity is insufficient to override the absence of malicious findings.
Conclusion
This package exhibits only scanner noise: code-smell YARA rules on standard JavaScript and XIOC false positives from property access chains. No tool poisoning, credential access, or network exfiltration was detected.
Key Reasons
- Zero tool-poisoning findings detected
- Zero credential-access findings
- Zero actual network findings (XIOC domains are property access chains)
- All code-smell findings are low-severity YARA postinstall rules
False Positive Considerations
- XIOC property access chains misread as domains (date.now, task.id, images.map)
- YARA postinstall code-smell rules matching standard Node.js patterns
- All findings are low-severity code-smell or false-positive IoC patterns
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 92%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace