MCP Registry

@pionex/pionex-trade-mcp

0034bf49-c9cd-5610-b897-1384c4f21381 | v0.2.51
45/ 100
MEDIUM risk
No change since v0.2.52
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (45/100) still counts them.

Analysis record

Analysed
2 months ago
Version
v0.2.51
Artifact
SHA256 2C2…5C0
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

7 detail rows

Finding Categories

5
Network

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Tool Poisoning Assessment

This package has zero tool-poisoning findings. The findings summary explicitly shows "tool-poisoning":"0". This is the most critical indicator for MCP security - tool poisoning is the defining threat vector, and its complete absence strongly indicates this is not a malicious package. There are no hidden AI directives, no invisible Unicode characters, and no XML-style instruction tags in tool metadata.

Credential and Network Access

The package description explicitly states it "reads credentials from ~/.pionex/config.toml". This is documented, expected behavior for a trading MCP server that needs API credentials to interact with the Pionex exchange. There is no evidence of credential exfiltration architecture. The network findings show only NET-FETCH-dist/index.js:880 - a fetch call in the bundled dist file, which is normal for an MCP server communicating with external APIs.

All detected network destinations are legitimate:

  • XIOC-URL-https://api.pionex.com - The official Pionex API endpoint
  • XIOC-URL-https://github.com/pionex-official/pionex-open-api/blob/main/openapi_bot.yaml - Pionex's official OpenAPI specification on GitHub

There is no combination of credential-access plus network calls to unknown domains, which would indicate exfiltration.

IoC False Positives

The 30 IoC findings are overwhelmingly false positives from known CVEQ noise patterns:

  • Property access chains misread as domains: XIOC-DOMAIN-parsed.values.help, XIOC-DOMAIN-cli.help, XIOC-DOMAIN-request.params.name
  • Source map filenames: XIOC-DOMAIN-clients.map, XIOC-DOMAIN-index.js.map
  • Filenames misread as domains: XIOC-DOMAIN-createfuturesgridorderdata.properties

The 19 malware-signature findings are from bundled dependencies in dist/index.js, which is expected for any packaged JavaScript application. Without tool poisoning or suspicious network behavior, malware signatures alone are noise.

Strongest Counterargument

The strongest counterargument is the presence of 19 malware-signature findings and 30 IoC findings, totaling 61 findings overall. However, this pattern matches known false positive drivers: bundled dependencies in dist/ files trigger multiplicative YARA matches, and the IoC extractor produces garbage from property access chains and filenames. The absence of tool poisoning, the documented credential scope, and legitimate network destinations override the finding count. CVEQ's own documentation states that confirmed false positives average risk score 83.2 due to this exact scoring inflation problem.

Conclusion

This is a legitimate Pionex trading MCP server. The findings are entirely explainable as false positives from bundled code and IoC extraction noise.

Key Reasons

  • Zero tool-poisoning findings - the defining MCP threat is absent
  • All network destinations are legitimate (api.pionex.com, github.com)
  • Credential access is documented and matches stated purpose (~/.pionex/config.toml)
  • IoC findings are property access chains and filenames, not real domains
  • Malware signatures are from bundled dist/ dependencies

False Positive Considerations

  • IoC extractor misreading property chains as domains (parsed.values.help, request.params.name)
  • Source map filenames detected as domains (clients.map, index.js.map)
  • Bundled dependencies in dist/index.js triggering malware signatures
  • IoC count inflation from legitimate URLs (github.com, api.pionex.com)

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

MCP version history

Risk trend by version

5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
45
Change since first
-5
Change from previous
No change
Versions:
First analyzed version
0.2.47
Apr 30, 2026
Risk range
45 to 50
Across analyzed versions
Latest analyzed version
0.2.51
Jul 24, 2026
Selected version
medium
Version
v0.2.51
2 months ago
Risk score
45
Findings
7
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Pionex MCP Server - reads credentials from ~/.pionex/config.toml

Frequently Asked Questions