The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.
No individual score drivers were recorded for this analysis.
Analysis record
- Analysed
- Today
- Version
- v2.4.0
- Artifact
- SHA256 57A…980
- Source
- Findings (non-IoC)
Is @kya-os/cli safe?
@kya-os/cli is a command-line tool for setting up and managing KYA-OS environments. It operates as an MCP server to provide tools that an AI agent can call. The package declares no special host permissions. Its primary documented network destination is agents.kya-os.ai. This endpoint aligns perfectly with the stated purpose of connecting to the KYA-OS agent infrastructure.
The scanner flagged 177 indicators of compromise alongside 85 code-smell matches. A genuine cluster of this size would indicate a heavily instrumented package phoning home to unknown servers. The single network finding points to a fetch call inside dist/sidecar/sidecar/src/conformance/reference/reference-adapter.js. The extracted domains include literal markdown filenames like 2026-08-27-rust-cli-rewrite-design.md and code fragments like def.in. These are regex artifacts. The extraction tool simply matched standard JavaScript syntax and documentation references.
The scanner tripped on bundled dependencies and basic language features. A pattern looking for web addresses will easily match a variable named def.internal or a markdown file referenced in a string. Code-smell rules fired on standard Node.js patterns common in any non-trivial CLI tool. Zero tool-poisoning matches exist. Zero credential-access findings exist. There is absolutely no exfiltration architecture present in the codebase. The package is clean.
No Findings
All security checks passed
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The @kya-os/cli package presents a classic case of scanner noise overwhelming a benign codebase. With zero tool-poisoning findings, there is no evidence of hidden AI directives or manipulation attempts embedded in tool descriptions. The package defines tools for KYA-OS setup, and the scanner correctly identified no malicious instructions aimed at the AI agent.
Credential scope is entirely absent. The findings summary shows zero secret detections and zero credential-access matches. The code does not attempt to read sensitive paths like .ssh, .aws, or .kube, nor does it target specific environment variables like GITHUB_TOKEN or AWS_SECRET_ACCESS_KEY. This eliminates the most common MCP attack vector, which is environment variable exfiltration.
Network access is minimal and expected. The only medium-severity network finding is NET-FETCH-dist/sidecar/sidecar/src/conformance/reference/reference-adapter.js-99. This points to a standard fetch call within a conformance reference adapter. The primary extracted network endpoint is agents.kya-os.ai, which directly matches the package's stated purpose of managing KYA-OS environments. The remaining 176 indicators of compromise are entirely spurious. The extracted endpoint list includes literal documentation files like 2026-08-27-rust-cli-rewrite-design.md and oauth-to-oauth2.md. It also includes code fragments like def.in, inst.rest, and inst.safe. These are well-known false positives from the IoC extractor matching variable names, method calls, and markdown filenames against domain regexes. Legitimate domains like colinhacks.com (the creator of Zod), emailregex.com, and blog.stevenlevithan.com are documentation links bundled within the dependency tree.
The 85 code-smell findings are uniformly low severity. These rules fire on basic Node.js patterns like process.env reads, fetch calls, and filesystem operations. In a bundled dist/ directory containing hundreds of transitive dependencies, these matches are multiplicative noise. A single webpack bundle can easily trigger dozens of code-smell rules simply by including standard libraries.
The strongest counterargument to a clean verdict is the sheer volume of findings. A total of 263 findings with 178 at medium severity looks alarming on the surface. An analyst glancing at the summary might assume the package is heavily instrumented with telemetry or exfiltration logic. However, examining the actual file paths and extracted strings reveals the truth. The medium-severity findings are almost exclusively IoC matches on bundled JavaScript. The code-smell findings are low-severity noise. When you strip away the regex artifacts and bundled dependency matches, the underlying package contains exactly one network call to its own documented API and zero malicious behavior. The high finding count is a product of the scanner's sensitivity to bundled code, not an indicator of compromise.
Key Reasons
- Zero tool-poisoning findings confirm no hidden AI directives
- Zero credential-access or secret findings eliminate exfiltration risk
- Single network finding points to the documented agents.kya-os.ai endpoint
- 177 IoC findings are regex artifacts matching code fragments and markdown filenames
- 85 code-smell findings are low-severity noise from bundled Node.js dependencies
False Positive Considerations
- IoC extractor matching code fragments like def.in and inst.rest as domains
- Regex matching markdown filenames like 2026-08-27-rust-cli-rewrite-design.md as network endpoints
- Code-smell rules firing on standard Node.js patterns in bundled dist dependencies
- Multiplicative false positives from transitive dependencies in webpack bundles
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 85%.
MCP version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace