MCP Registry

shadow-claw

05af1c7a-973c-562c-96c1-d350860b1939 | v1.41.1
100/ 100
CRITICAL risk
No change since v1.41.0
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v1.41.1
Artifact
SHA256 DCB…FF8
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 441 · highest severity first

YARA Rule Matches

12 rules
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 1
dist/lib/orchestrator-DKHCoikY.js.map
-
LOWpostinstall persistence mechanism 247
src/subsystems/git/git.tssrc/config/config.tsdist/lib/subsystems/tools/task-scheduler.d.ts +244 more
-
LOWRedirectToUnknownPath 7
dist/cli/chunk-BgmYA83Z.jssrc/service-worker/share-target.tssrc/server/routes/docs.test.ts +4 more
-
LOWcredential env files 150
src/server/utils/proxy-helpers.tssrc/cli/utils/resolve-cache-dir.tsdist/cli/chunk-C71FSYx02.js +147 more
-
LOWServerCertificatesNotVerified 1
src/cli/utils/webrtc-control-client.ts
-
LOWLocalStorageShouldNotBeUsed 32
src/utils/namespacedStorage.test.tsdist/public/docs/example/article/index.htmldist/cli/chunk-Bjqh5_SU2.js +29 more
-
LOWDebuggerStatementsShouldNotBeUsed 10
dist/public/docs/architecture/storage.mddist/lib/markdown-k8wA9LKy.js.mapdist/lib/markdown-k8wA9LKy.js +7 more
-
LOWcredential aws profile 1
dist/electron/main.cjs
-
LOWUsingCommandLineArguments 18
src/cli/tools/patch-service-worker-trusted-types.tsdist/server.jssrc/server/server.ts +15 more
-
LOWpostinstall file download 2
src/core/control-plane-client.test.tsdist/lib/tools-BQpz4Hkp.js
-
LOWNoUseEval 2
dist/lib/orchestrator-DKHCoikY.jsdist/cli/chunk-FEL5dv0w2.js
-
LOWNoUseWeakRandom 88
src/server/utils/openai-sse.tssrc/cli/site-config/apply.test.tsdist/lib/shadow-claw-files-xGGhsHNH.js +85 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

3,129 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

1
Malware Signatures
42
Secrets
391
Network
3,129
IoC Indicators

YARA Rules Matched

12 rules(559 hits)
supply chain sourcemap appended iife postinstall persistence mechanism RedirectToUnknownPath credential env files ServerCertificatesNotVerified LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed credential aws profile UsingCommandLineArguments postinstall file download NoUseEval NoUseWeakRandom

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The shadow-claw package presents a massive volume of scanner findings, but a close look at the actual evidence reveals a pattern dominated by false positives from bundled dependencies and aggressive code-smell rules. The defining threat for any MCP server is tool poisoning, and this bundle contains exactly one tool-poisoning finding. The match is titled MCP-TOOL-TOOL-POISONING-dist/server.js-992 and resides in the compiled output directory. The evidence bundle provides no description text for this match, making it impossible to confirm whether it contains hidden directives aimed at an AI agent or if the scanner simply flagged a legitimate tool definition within the bundled JavaScript. Without the actual text of the alleged instruction, we cannot treat this as a confirmed poisoning attempt.

Credential and network access patterns further support a benign assessment. The bundle lists 41 secret findings, almost all bearing the title MCP-TRANSPORT-HARDCODED-TOKEN and located in test files such as src/config/settings-backup.test.ts, src/worker/utils/executeTool.test.ts, and src/subsystems/git/git.test.ts. Hardcoded tokens in test files are standard practice for mock data and do not represent exposed secrets. The few matches in source files like src/subsystems/git/git.ts and src/shell/shell.ts align directly with the package's stated purpose of managing git and shell operations. There are no credential-access findings targeting sensitive environment paths like .ssh, .aws, or .kube.

The network endpoints extracted from the package are largely garbage. The list includes strings like 00-08-00.md, 20file.md, and 20name.md, which clearly indicates the IoC extractor misidentified static text or markdown filenames as domain names. There are no legitimate external domains that suggest an exfiltration architecture.

The strongest counterargument to a clean bill of health is the metadata. The developer name is listed as "GitHub Actions", which is a generic identifier that could indicate name squatting or an attempt to impersonate a trusted entity. The package also has zero recorded users. These are valid reasons for suspicion in the MCP environment. However, metadata quirks do not override the actual code behavior. The overwhelming majority of the 9,014 findings are low-severity code-smell matches and IoC noise from the dist/ directory. The secret findings are confined to test files, and there is no evidence of the package reading sensitive paths or sending data to unknown external domains. The single tool-poisoning match lacks the descriptive evidence required to confirm malicious intent. Until the actual text of the dist/server.js match is reviewed, the findings remain noise.

Key Reasons

  • Single tool-poisoning finding in dist/server.js lacks description text to confirm hidden AI directives
  • 41 secret findings are almost entirely hardcoded tokens in .test.ts mock data files
  • Network endpoints are garbage extractions from markdown filenames and static strings
  • No credential-access findings targeting sensitive paths like .ssh, .aws, or .kube
  • 9014 total findings are overwhelmingly code-smell and IoC noise from the bundled dist/ directory

False Positive Considerations

  • Bundled dist/ directory generating massive IoC and code-smell noise
  • IoC extractor misidentifying markdown filenames and static strings as network endpoints
  • MCP-TRANSPORT-HARDCODED-TOKEN matches confined to .test.ts mock data files
  • Single tool-poisoning finding lacks description text to confirm hidden directives

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 75%.

MCP version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
100
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
1.36.0
Sep 18, 2026
Risk range
100 to 100
Across analyzed versions
Latest analyzed version
1.41.1
Sep 29, 2026
Selected version
critical
Version
v1.41.1
2 days ago
Risk score
100
Findings
9015
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

ShadowClaw - multi-runtime AI assistant.

Frequently Asked Questions