MCP Registry

@erdify/mcp-server

000ec537-c9e2-54f5-955e-9efd5f414f20 | v0.4.0
34/ 100
LOW risk
-14 since v0.3.0
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
1 months ago
Version
v0.4.0
Artifact
SHA256 FB4…B35
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

3 detail rows

Finding Categories

1
Network

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Tool Poisoning Assessment

No tool-poisoning findings were detected (threat_indicators shows 'tool-poisoning': 0). This is a critical negative finding - there are no hidden AI manipulation directives embedded in tool descriptions. The package contains no XML-style instruction tags, invisible Unicode characters, or AI-targeted commands that would constitute tool poisoning.

Credential and Network Access

The findings show zero credential-access detections and zero secret findings. The code does not target sensitive paths like .ssh, .aws/credentials, .kube/config, or specific secret environment variables. This is consistent with an ERD diagram tool that doesn't need to harvest credentials.

The single network finding (NET-FETCH-dist/index.js:10) is a fetch call in the bundled distribution file. The IoC findings show URLs pointing to http://erdify-app.kro.kr/api, which matches the documented API endpoint from the package description ("MCP server for ERDify"). This is legitimate API communication, not exfiltration to an unknown domain.

IoC Findings Are False Positives

All 17 IoC findings are classic extractor garbage. The "domains" detected include:

  • t.sourcecolumnids.map, t.targetcolumnids.map, t.columnids.map, t.indexes.map, t.relationships.map - These are JavaScript property access chains, not real domains
  • i.content.entities.map - Another property access chain
  • date.now - A JavaScript method call
  • your-server.com - A placeholder from documentation or example code

The XIOC extractor is misreading JavaScript object property access (e.g., t.columnids.map) as domain names. This is a well-documented false positive pattern in the CVEQ scanner.

Strongest Counterargument

The counterargument would be that 17 IoC findings is a lot, and the single NET-FETCH finding could indicate exfiltration. However, this doesn't change the conclusion because: (1) IoC count alone is meaningless in bundled packages - the nature of the findings matters, not the quantity, and (2) the network call goes to the documented API endpoint, not an unknown domain. There is no credential harvesting combined with suspicious network calls, which is the actual exfiltration signal.

Conclusion

This is a legitimate MCP server for ERD diagram manipulation. The findings are entirely false positives from the IoC extractor misinterpreting JavaScript code as network indicators.

Key Reasons

  • Zero tool-poisoning findings - no hidden AI directives detected
  • Zero credential-access findings - no sensitive path targeting
  • All 17 IoC findings are property access chains misread as domains
  • Network call targets documented API endpoint (erdify-app.kro.kr)
  • No malware signatures or obfuscation detected

False Positive Considerations

  • XIOC-DOMAIN findings are JavaScript property access chains (t.columnids.map, t.sourcecolumnids.map, etc.)
  • your-server.com is a documentation placeholder
  • date.now is a JavaScript method call, not a domain
  • Bundled dist/ file triggers expected network findings

Reviewed 2026-06-01; recommended action: no action; model confidence 85%.

MCP version history

Risk trend by version

8 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
34
Change since first
-16
Change from previous
-14
Versions:
First analyzed version
0.2.1
Jun 1, 2026
Risk range
34 to 50
Across analyzed versions
Latest analyzed version
0.4.0
Aug 8, 2026
Selected version
low
Version
v0.4.0
1 months ago
Risk score
34
Findings
3
Change vs previous
-14

Pick any point on the chart to explore that version's code below.

About This Extension

MCP server for [ERDify](https://erdify-app.kro.kr) — lets AI assistants (Claude, Cursor, etc.) read and modify your ERD diagrams using natural language.

Frequently Asked Questions