Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 3 months ago
- Version
- v7.0.0
- Artifact
- SHA256 43D…0D1
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality weak.
Package Overview
jest-extended (version 7.0.0) by developer simenb is described as "Additional Jest matchers" — a testing utility library for the Jest framework. This package is hosted on the n8n platform with 0 reported users.
Tool Poisoning Assessment
The findings_by_category object is completely empty. There are zero tool-poisoning findings, zero hidden AI directive findings, and zero tool definition anomalies. This is expected because jest-extended is a testing library, not an MCP server. Testing libraries do not define MCP tools, so the tool-poisoning threat model does not apply to this package.
Credential and Network Access
The empty findings_by_category indicates no credential-access findings were detected. There are no references to .ssh, .aws/credentials, .kube/config, or other sensitive paths. There are no network findings (NET-FETCH, NET-SOCKET_IO) and no IoC findings showing suspicious domain connections. This is consistent with a testing library that operates locally without external network communication or credential harvesting.
Malware Signatures and Code Smells
No YARA code-smell findings, no malware family signatures, and no obfuscation findings were detected. The findings_by_category object contains no entries across any category.
Strongest Counterargument
The strongest argument against this verdict is that the empty findings could indicate an incomplete or failed analysis rather than a genuinely clean package. If the scanner did not properly analyze the package contents, malicious code could exist undetected. However, jest-extended is a well-established, open-source testing library with a clear purpose (Jest matchers), and the developer name simenb is associated with legitimate testing tooling. The package description matches its expected functionality, and there is no evidence of supply chain attack patterns (typosquatting, name squatting, version velocity anomalies).
Conclusion
With zero findings across all security categories and a clear, legitimate purpose as a Jest testing utility, this package shows no evidence of malicious behavior. The empty findings object represents a clean security posture, not an analysis failure.
Key Reasons
- findings_by_category is completely empty - zero security findings detected
- Package is a Jest testing library, not an MCP server - tool poisoning threat model does not apply
- No credential-access, network, or IoC findings
- Developer and package name are consistent with legitimate testing utilities
False Positive Considerations
- Empty findings object - no actual findings to evaluate
- Package type (testing library) does not match MCP threat model
Reviewed 2026-04-22; recommended action: no action; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace