MCP Registry

@microsoft/agents-a365-tooling

0d8c651e-2e05-5d22-9ae9-2db1471eaf46 | v2.0.0-preview.1
50/ 100
MEDIUM risk
-2 since v1.1.0-preview.7
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.

Analysis record

Analysed
Today
Version
v2.0.0-preview.1
Artifact
SHA256 50C…378
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

33 detail rows

YARA Rule Matches

7 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 2
dist/esm/configuration/ToolingConfiguration.jsdist/cjs/configuration/ToolingConfiguration.js
-
LOWpostinstall file download 3
dist/cjs/McpToolServerConfigurationService.jsREADME.mddist/esm/McpToolServerConfigurationService.js
-
LOWUsingCommandLineArguments 4
dist/cjs/McpToolServerConfigurationService.jsdist/esm/McpToolServerConfigurationService.d.tsdist/cjs/McpToolServerConfigurationService.d.ts +1 more
-
LOWpostinstall environment access 4
dist/cjs/Utility.d.tsdist/esm/McpToolServerConfigurationService.d.tsdist/esm/Utility.d.ts +1 more
-
LOWpostinstall obfuscation 2
dist/esm/Utility.jsdist/cjs/Utility.js
-
LOWpostinstall network communication 11
dist/cjs/McpToolServerConfigurationService.jsdist/esm/McpToolServerConfigurationService.jsdist/cjs/models/ChatHistoryMessage.d.ts +8 more
-
LOWpostinstall system command 3
README.mddist/esm/models/ChatHistoryMessage.d.tsdist/cjs/models/ChatHistoryMessage.d.ts
-

Finding Categories

2
Network

YARA Rules Matched

7 rules(29 hits)
credential env files postinstall file download UsingCommandLineArguments postinstall environment access postinstall obfuscation postinstall network communication postinstall system command

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Tool Poisoning Assessment:

There are zero tool-poisoning findings in this package. The findings summary shows tool-poisoning:0. This is the most critical finding for MCP security, and its absence is strong evidence against malicious intent.

Credential and Network Access:

The findings summary shows secret:0 and credential-access findings are absent. No code reads sensitive paths like .ssh/, .aws/credentials, or .kube/config. The only legitimate URL detected is https://agent365.svc.cloud.microsoft (from finding XIOC-URL-https://agent365.svc.cloud.microsoft';), which is a Microsoft internal service domain consistent with the package's stated purpose as "Agent 365 Tooling SDK."

IoC False Positives:

All 46 IoC findings are scanner artifacts, not real indicators:

  • XIOC-DOMAIN-chathistorymessage.js.map, XIOC-DOMAIN-chatmessagerequest.d.ts.map, XIOC-DOMAIN-mcptoolserverconfigurationservice.d.ts.map — source map file names misread as domains
  • XIOC-DOMAIN-axios.post — a method call misread as a domain
  • XIOC-DOMAIN-conversation.id — a property access chain misread as a domain
  • XIOC-DOMAIN-changelog.md, XIOC-DOMAIN-readme.md, XIOC-DOMAIN-license.md — documentation file names misread as domains
  • XIOC-DOMAIN-www.npmjs.com — legitimate npm registry domain

These patterns match the known XIOC false-positive behavior where the extractor confuses JavaScript syntax, file names, and property chains with domain names.

Malware Signatures:

The 29 malware-signature findings with no actual malware detections are consistent with YARA code-smell rules firing on bundled/minified TypeScript output. Without specific rule names showing credential theft or exfiltration patterns, these are noise.

Strongest Counterargument:

The high severity count (35 high, 48 medium) might suggest concern. However, severity is inflated by the sheer volume of false-positive IoC detections, not by evidence of malicious behavior. The package is published by microsoft1es (Microsoft Enterprise & Services division) under the @microsoft/ scope, and the only real network destination (agent365.svc.cloud.microsoft) is a Microsoft internal service. No evidence exists of tool poisoning, credential exfiltration, or suspicious third-party domains.

Key Reasons

  • Zero tool-poisoning findings in an MCP package
  • Zero secret/credential-access findings
  • All IoC detections are false positives from file names and method calls
  • Publisher is Microsoft (@microsoft/ scope, microsoft1es developer)
  • Only real URL is Microsoft internal service (agent365.svc.cloud.microsoft)

False Positive Considerations

  • XIOC misclassifying source map file names as domains
  • XIOC misclassifying method calls (axios.post) as domains
  • XIOC misclassifying property access (conversation.id) as domains
  • XIOC misclassifying documentation file names as domains

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

MCP version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
50
Change since first
-2
Change from previous
-2
Versions:
First analyzed version
1.0.0
May 1, 2026
Risk range
50 to 52
Across analyzed versions
Latest analyzed version
2.0.0-preview.1
Oct 1, 2026
Selected version
medium
Version
v2.0.0-preview.1
Today
Risk score
50
Findings
33
Change vs previous
-2

Pick any point on the chart to explore that version's code below.

About This Extension

Agent 365 Tooling SDK for AI agents built with TypeScript/Node.js

Frequently Asked Questions