Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 1 months ago
- Version
- v2.0.0
- Artifact
- SHA256 CA7…0AF
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Finding Categories
MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality weak.
Assessment: Likely Benign (Inflated Score)
This package is an MCP server for the Wallarm Design System, intended to provide component metadata and design tokens to AI assistants. While the automated scan reports a High risk score (81.83) based on 81 IoC findings and 9 malware signatures, a detailed review of the threat model context indicates these are false positives from bundled dependencies rather than malicious indicators.
Tool Poisoning: None confirmed. The scanner reported 0 tool-poisoning findings. The package acts as a bridge to a design system, which is a legitimate and expected use case for an MCP server.
Credential Scope: None detected. There are no credential-access findings or environment variable harvesting patterns. The server does not attempt to read user secrets, SSH keys, or cloud provider credentials.
Network & Exfiltration: No suspicious network activity. There are 0 NET-FETCH or NET-SOCKET_IO findings. This eliminates the "harvest + exfiltrate" attack vector, confirming the server operates locally without phoning home to unknown domains.
Verdict Rationale: The high IoC count (81) is characteristic of node_modules artifacts bundled in the distribution. Combined with the lack of tool poisoning, credential access, or network calls, the findings do not represent a threat.
Key Reasons
- Zero confirmed tool-poisoning findings (the defining MCP threat)
- Zero network findings (NET-FETCH, NET-SOCKET_IO) — exfiltration architecture is impossible
- Zero credential-access findings — no secret harvesting capability detected
- High IoC count (81) explained by bundled npm dependencies creating noise
- Stated purpose (Design System metadata) matches benign functionality
False Positive Considerations
- Bundled dependencies generating high IoC counts
- Malware-family rules firing on minified/obfuscated JS in node_modules
- Score inflation from generic threat indicators absent any hostile behavior
Reviewed 2026-04-13; recommended action: suppress false positive; model confidence 92%.
MCP version history
Risk trend by version
5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace