@microsoft/agents-a365-tooling
The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.
Analysis record
- Analysed
- Today
- Version
- v2.0.0-preview.1
- Artifact
- SHA256 50C…378
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
7 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 2 | dist/esm/configuration/ToolingConfiguration.jsdist/cjs/configuration/ToolingConfiguration.js | - |
| LOW | postinstall file download | 3 | dist/cjs/McpToolServerConfigurationService.jsREADME.mddist/esm/McpToolServerConfigurationService.js | - |
| LOW | UsingCommandLineArguments | 4 | dist/cjs/McpToolServerConfigurationService.jsdist/esm/McpToolServerConfigurationService.d.tsdist/cjs/McpToolServerConfigurationService.d.ts +1 more | - |
| LOW | postinstall environment access | 4 | dist/cjs/Utility.d.tsdist/esm/McpToolServerConfigurationService.d.tsdist/esm/Utility.d.ts +1 more | - |
| LOW | postinstall obfuscation | 2 | dist/esm/Utility.jsdist/cjs/Utility.js | - |
| LOW | postinstall network communication | 11 | dist/cjs/McpToolServerConfigurationService.jsdist/esm/McpToolServerConfigurationService.jsdist/cjs/models/ChatHistoryMessage.d.ts +8 more | - |
| LOW | postinstall system command | 3 | README.mddist/esm/models/ChatHistoryMessage.d.tsdist/cjs/models/ChatHistoryMessage.d.ts | - |
Finding Categories
YARA Rules Matched
7 rules(29 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Tool Poisoning Assessment:
There are zero tool-poisoning findings in this package. The findings summary shows tool-poisoning:0. This is the most critical finding for MCP security, and its absence is strong evidence against malicious intent.
Credential and Network Access:
The findings summary shows secret:0 and credential-access findings are absent. No code reads sensitive paths like .ssh/, .aws/credentials, or .kube/config. The only legitimate URL detected is https://agent365.svc.cloud.microsoft (from finding XIOC-URL-https://agent365.svc.cloud.microsoft';), which is a Microsoft internal service domain consistent with the package's stated purpose as "Agent 365 Tooling SDK."
IoC False Positives:
All 46 IoC findings are scanner artifacts, not real indicators:
XIOC-DOMAIN-chathistorymessage.js.map,XIOC-DOMAIN-chatmessagerequest.d.ts.map,XIOC-DOMAIN-mcptoolserverconfigurationservice.d.ts.map— source map file names misread as domainsXIOC-DOMAIN-axios.post— a method call misread as a domainXIOC-DOMAIN-conversation.id— a property access chain misread as a domainXIOC-DOMAIN-changelog.md,XIOC-DOMAIN-readme.md,XIOC-DOMAIN-license.md— documentation file names misread as domainsXIOC-DOMAIN-www.npmjs.com— legitimate npm registry domain
These patterns match the known XIOC false-positive behavior where the extractor confuses JavaScript syntax, file names, and property chains with domain names.
Malware Signatures:
The 29 malware-signature findings with no actual malware detections are consistent with YARA code-smell rules firing on bundled/minified TypeScript output. Without specific rule names showing credential theft or exfiltration patterns, these are noise.
Strongest Counterargument:
The high severity count (35 high, 48 medium) might suggest concern. However, severity is inflated by the sheer volume of false-positive IoC detections, not by evidence of malicious behavior. The package is published by microsoft1es (Microsoft Enterprise & Services division) under the @microsoft/ scope, and the only real network destination (agent365.svc.cloud.microsoft) is a Microsoft internal service. No evidence exists of tool poisoning, credential exfiltration, or suspicious third-party domains.
Key Reasons
- Zero tool-poisoning findings in an MCP package
- Zero secret/credential-access findings
- All IoC detections are false positives from file names and method calls
- Publisher is Microsoft (@microsoft/ scope, microsoft1es developer)
- Only real URL is Microsoft internal service (agent365.svc.cloud.microsoft)
False Positive Considerations
- XIOC misclassifying source map file names as domains
- XIOC misclassifying method calls (axios.post) as domains
- XIOC misclassifying property access (conversation.id) as domains
- XIOC misclassifying documentation file names as domains
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.
MCP version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace