MCP Registry

@wallarm-org/mcp

002997ef-5e2c-567f-8e4c-b71c8ad7739e | v2.0.0
38/ 100
LOW risk
No change since v1.4.1
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
1 months ago
Version
v2.0.0
Artifact
SHA256 CA7…0AF
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1 detail row

Finding Categories

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

Assessment: Likely Benign (Inflated Score)

This package is an MCP server for the Wallarm Design System, intended to provide component metadata and design tokens to AI assistants. While the automated scan reports a High risk score (81.83) based on 81 IoC findings and 9 malware signatures, a detailed review of the threat model context indicates these are false positives from bundled dependencies rather than malicious indicators.

Tool Poisoning: None confirmed. The scanner reported 0 tool-poisoning findings. The package acts as a bridge to a design system, which is a legitimate and expected use case for an MCP server.

Credential Scope: None detected. There are no credential-access findings or environment variable harvesting patterns. The server does not attempt to read user secrets, SSH keys, or cloud provider credentials.

Network & Exfiltration: No suspicious network activity. There are 0 NET-FETCH or NET-SOCKET_IO findings. This eliminates the "harvest + exfiltrate" attack vector, confirming the server operates locally without phoning home to unknown domains.

Verdict Rationale: The high IoC count (81) is characteristic of node_modules artifacts bundled in the distribution. Combined with the lack of tool poisoning, credential access, or network calls, the findings do not represent a threat.

Key Reasons

  • Zero confirmed tool-poisoning findings (the defining MCP threat)
  • Zero network findings (NET-FETCH, NET-SOCKET_IO) — exfiltration architecture is impossible
  • Zero credential-access findings — no secret harvesting capability detected
  • High IoC count (81) explained by bundled npm dependencies creating noise
  • Stated purpose (Design System metadata) matches benign functionality

False Positive Considerations

  • Bundled dependencies generating high IoC counts
  • Malware-family rules firing on minified/obfuscated JS in node_modules
  • Score inflation from generic threat indicators absent any hostile behavior

Reviewed 2026-04-13; recommended action: suppress false positive; model confidence 92%.

MCP version history

Risk trend by version

5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
38
Change since first
-2
Change from previous
No change
Versions:
First analyzed version
1.2.0
Apr 24, 2026
Risk range
38 to 41
Across analyzed versions
Latest analyzed version
2.0.0
Aug 15, 2026
Selected version
low
Version
v2.0.0
1 months ago
Risk score
38
Findings
1
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

MCP server for Wallarm Design System — provides component metadata, props, variants, and design tokens to AI assistants

Frequently Asked Questions