Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 1 months ago
- Version
- v0.4.0
- Artifact
- SHA256 FB4…B35
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Finding Categories
MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Tool Poisoning Assessment
No tool-poisoning findings were detected (threat_indicators shows 'tool-poisoning': 0). This is a critical negative finding - there are no hidden AI manipulation directives embedded in tool descriptions. The package contains no XML-style instruction tags, invisible Unicode characters, or AI-targeted commands that would constitute tool poisoning.
Credential and Network Access
The findings show zero credential-access detections and zero secret findings. The code does not target sensitive paths like .ssh, .aws/credentials, .kube/config, or specific secret environment variables. This is consistent with an ERD diagram tool that doesn't need to harvest credentials.
The single network finding (NET-FETCH-dist/index.js:10) is a fetch call in the bundled distribution file. The IoC findings show URLs pointing to http://erdify-app.kro.kr/api, which matches the documented API endpoint from the package description ("MCP server for ERDify"). This is legitimate API communication, not exfiltration to an unknown domain.
IoC Findings Are False Positives
All 17 IoC findings are classic extractor garbage. The "domains" detected include:
t.sourcecolumnids.map,t.targetcolumnids.map,t.columnids.map,t.indexes.map,t.relationships.map- These are JavaScript property access chains, not real domainsi.content.entities.map- Another property access chaindate.now- A JavaScript method callyour-server.com- A placeholder from documentation or example code
The XIOC extractor is misreading JavaScript object property access (e.g., t.columnids.map) as domain names. This is a well-documented false positive pattern in the CVEQ scanner.
Strongest Counterargument
The counterargument would be that 17 IoC findings is a lot, and the single NET-FETCH finding could indicate exfiltration. However, this doesn't change the conclusion because: (1) IoC count alone is meaningless in bundled packages - the nature of the findings matters, not the quantity, and (2) the network call goes to the documented API endpoint, not an unknown domain. There is no credential harvesting combined with suspicious network calls, which is the actual exfiltration signal.
Conclusion
This is a legitimate MCP server for ERD diagram manipulation. The findings are entirely false positives from the IoC extractor misinterpreting JavaScript code as network indicators.
Key Reasons
- Zero tool-poisoning findings - no hidden AI directives detected
- Zero credential-access findings - no sensitive path targeting
- All 17 IoC findings are property access chains misread as domains
- Network call targets documented API endpoint (erdify-app.kro.kr)
- No malware signatures or obfuscation detected
False Positive Considerations
- XIOC-DOMAIN findings are JavaScript property access chains (t.columnids.map, t.sourcecolumnids.map, etc.)
- your-server.com is a documentation placeholder
- date.now is a JavaScript method call, not a domain
- Bundled dist/ file triggers expected network findings
Reviewed 2026-06-01; recommended action: no action; model confidence 85%.
MCP version history
Risk trend by version
8 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace