shadow-claw
The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v1.41.1
- Artifact
- SHA256 DCB…FF8
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
12 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | supply chain sourcemap appended iife | 1 | dist/lib/orchestrator-DKHCoikY.js.map | - |
| LOW | postinstall persistence mechanism | 247 | src/subsystems/git/git.tssrc/config/config.tsdist/lib/subsystems/tools/task-scheduler.d.ts +244 more | - |
| LOW | RedirectToUnknownPath | 7 | dist/cli/chunk-BgmYA83Z.jssrc/service-worker/share-target.tssrc/server/routes/docs.test.ts +4 more | - |
| LOW | credential env files | 150 | src/server/utils/proxy-helpers.tssrc/cli/utils/resolve-cache-dir.tsdist/cli/chunk-C71FSYx02.js +147 more | - |
| LOW | ServerCertificatesNotVerified | 1 | src/cli/utils/webrtc-control-client.ts | - |
| LOW | LocalStorageShouldNotBeUsed | 32 | src/utils/namespacedStorage.test.tsdist/public/docs/example/article/index.htmldist/cli/chunk-Bjqh5_SU2.js +29 more | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 10 | dist/public/docs/architecture/storage.mddist/lib/markdown-k8wA9LKy.js.mapdist/lib/markdown-k8wA9LKy.js +7 more | - |
| LOW | credential aws profile | 1 | dist/electron/main.cjs | - |
| LOW | UsingCommandLineArguments | 18 | src/cli/tools/patch-service-worker-trusted-types.tsdist/server.jssrc/server/server.ts +15 more | - |
| LOW | postinstall file download | 2 | src/core/control-plane-client.test.tsdist/lib/tools-BQpz4Hkp.js | - |
| LOW | NoUseEval | 2 | dist/lib/orchestrator-DKHCoikY.jsdist/cli/chunk-FEL5dv0w2.js | - |
| LOW | NoUseWeakRandom | 88 | src/server/utils/openai-sse.tssrc/cli/site-config/apply.test.tsdist/lib/shadow-claw-files-xGGhsHNH.js +85 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
12 rules(559 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The shadow-claw package presents a massive volume of scanner findings, but a close look at the actual evidence reveals a pattern dominated by false positives from bundled dependencies and aggressive code-smell rules. The defining threat for any MCP server is tool poisoning, and this bundle contains exactly one tool-poisoning finding. The match is titled MCP-TOOL-TOOL-POISONING-dist/server.js-992 and resides in the compiled output directory. The evidence bundle provides no description text for this match, making it impossible to confirm whether it contains hidden directives aimed at an AI agent or if the scanner simply flagged a legitimate tool definition within the bundled JavaScript. Without the actual text of the alleged instruction, we cannot treat this as a confirmed poisoning attempt.
Credential and network access patterns further support a benign assessment. The bundle lists 41 secret findings, almost all bearing the title MCP-TRANSPORT-HARDCODED-TOKEN and located in test files such as src/config/settings-backup.test.ts, src/worker/utils/executeTool.test.ts, and src/subsystems/git/git.test.ts. Hardcoded tokens in test files are standard practice for mock data and do not represent exposed secrets. The few matches in source files like src/subsystems/git/git.ts and src/shell/shell.ts align directly with the package's stated purpose of managing git and shell operations. There are no credential-access findings targeting sensitive environment paths like .ssh, .aws, or .kube.
The network endpoints extracted from the package are largely garbage. The list includes strings like 00-08-00.md, 20file.md, and 20name.md, which clearly indicates the IoC extractor misidentified static text or markdown filenames as domain names. There are no legitimate external domains that suggest an exfiltration architecture.
The strongest counterargument to a clean bill of health is the metadata. The developer name is listed as "GitHub Actions", which is a generic identifier that could indicate name squatting or an attempt to impersonate a trusted entity. The package also has zero recorded users. These are valid reasons for suspicion in the MCP environment. However, metadata quirks do not override the actual code behavior. The overwhelming majority of the 9,014 findings are low-severity code-smell matches and IoC noise from the dist/ directory. The secret findings are confined to test files, and there is no evidence of the package reading sensitive paths or sending data to unknown external domains. The single tool-poisoning match lacks the descriptive evidence required to confirm malicious intent. Until the actual text of the dist/server.js match is reviewed, the findings remain noise.
Key Reasons
- Single tool-poisoning finding in dist/server.js lacks description text to confirm hidden AI directives
- 41 secret findings are almost entirely hardcoded tokens in .test.ts mock data files
- Network endpoints are garbage extractions from markdown filenames and static strings
- No credential-access findings targeting sensitive paths like .ssh, .aws, or .kube
- 9014 total findings are overwhelmingly code-smell and IoC noise from the bundled dist/ directory
False Positive Considerations
- Bundled dist/ directory generating massive IoC and code-smell noise
- IoC extractor misidentifying markdown filenames and static strings as network endpoints
- MCP-TRANSPORT-HARDCODED-TOKEN matches confined to .test.ts mock data files
- Single tool-poisoning finding lacks description text to confirm hidden directives
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 75%.
MCP version history
Risk trend by version
4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace