MCP Registry

agentdb

by ruvnet
0dfc1a5a-5fb5-5f66-ac47-31700e6f7bb6 | v3.0.0-alpha.20
81/ 100
HIGH risk
+1 since v3.0.0-alpha.18
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
1 months ago
Version
v3.0.0-alpha.20
Artifact
SHA256 4B5…3C9
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

455 detail rows

YARA Rule Matches

14 rules
SeverityRuleHitsFilesMetadata
LOWNoUseEval 2
dist/src/db-fallback.d.tsdist/src/db-fallback.js
-
LOWNoUseWeakRandom 31
dist/src/controllers/AttentionService.jsdist/src/cli/commands/route.jsdist/src/controllers/MincutService.js +28 more
-
LOWpostinstall file download 15
dist/src/controllers/ReflexionMemory.jsdist/src/model/ModelCacheLoader.d.tsdist/src/controllers/HNSWIndex.js +12 more
-
LOWpostinstall obfuscation 49
dist/src/cli/commands/route.jsdist/src/controllers/ExplainableRecall.d.tsdist/src/optimizations/Quantization.js +46 more
-
LOWpostinstall system command 123
dist/src/controllers/SparsificationService.jsdist/src/cli/lib/simulation-runner.d.tsdist/src/types/database.types.js +120 more
-
LOWpostinstall crypto operations 33
dist/src/cli/commands/doctor.jsdist/src/controllers/MincutService.d.tsdist/src/core/QueryCache.d.ts +30 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 1
dist/src/cli/agentdb-cli.js
-
LOWpostinstall network communication 48
dist/src/backends/VectorBackend.d.tsdist/src/examples/quic-sync-example.jsLICENSE +45 more
-
LOWpostinstall file manipulation 94
dist/src/optimizations/Quantization.d.tsdist/src/cli/lib/report-generator.jsdist/src/utils/attention-metrics.js +91 more
-
LOWpostinstall registry modification 15
dist/src/cli/lib/simulation-registry.d.ts.mapdist/src/backends/rvf/SqlJsRvfBackend.d.tsdist/src/cli/lib/simulation-runner.js +12 more
-
LOWpostinstall environment access 6
dist/src/governance/RvfExperimentBranch.jsdist/src/backends/rvf/SelfLearningRvfBackend.jsdist/src/core/AgentDB.d.ts +3 more
-
LOWUsingCommandLineArguments 4
dist/src/examples/quic-sync-example.jsdist/src/benchmark/BenchmarkSuite.jsdist/src/cli/agentdb-cli.js +1 more
-
LOWcredential env files 17
dist/src/services/LLMRouter.jsdist/src/services/LLMRouter.d.tsscripts/postinstall.cjs +14 more
-
LOWpostinstall persistence mechanism 6
dist/src/security/path-security.d.tsdist/src/services/AttentionService.jsdist/src/mcp/agentdb-mcp-server.js +3 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

141 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

2
Secrets
7
Network
141
IoC Indicators

YARA Rules Matched

14 rules(444 hits)
NoUseEval NoUseWeakRandom postinstall file download postinstall obfuscation postinstall system command postinstall crypto operations UsingShellInterpreterWhenExecutingOSCommands postinstall network communication postinstall file manipulation postinstall registry modification postinstall environment access UsingCommandLineArguments credential env files postinstall persistence mechanism

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category unknown malware; evidence quality weak.

AgentDB v3 presents a critical risk score primarily due to a massive volume of malware signature findings (476) and network indicators (785). The scanner detected 2 secret findings, 2 network activity findings, and 5 code-smell hits, but found zero instances of tool poisoning. In the MCP ecosystem, this pattern—high malware counts with zero tool poisoning—strongly suggests bundle contamination. The 476 malware signatures likely originate from minified JavaScript dependencies or utility libraries (e.g., specialized math/DB kernels) being misidentified by YARA rules. Similarly, the 785 IoCs are almost certainly the 'IPv6 fragment' or 'property chain' false positives typical of obfuscated code. However, the 'unknown' status of the findings forces a cautious stance: without verification, we cannot distinguish between aggressive false positives and a sophisticated supply-chain delivery (e.g., 'Gupti' malware) inside the dist bundle. The recommendation is manual review of the dist/ build artifacts or runtime sandboxing.

Key Reasons

  • 476 malware signatures in dist/ likely false positives from minified deps
  • Zero tool-poisoning findings despite high-risk classification
  • High IoC count (785) consistent with property-access false positives
  • Unknown findings preventing automated clearance

False Positive Considerations

  • Minified/Bundled Dependencies
  • Generic YARA Malware Signatures
  • IPv6/Property-Access IoC Extraction Noise

Reviewed 2026-04-12; recommended action: reanalyze; model confidence 60%.

MCP version history

Risk trend by version

6 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
81
Change since first
-1
Change from previous
+1
Versions:
First analyzed version
3.0.0-alpha.12
May 5, 2026
Risk range
80 to 82
Across analyzed versions
Latest analyzed version
3.0.0-alpha.20
Jul 30, 2026
Selected version
high
Version
v3.0.0-alpha.20
2 months ago
Risk score
81
Findings
596
Change vs previous
+1

Pick any point on the chart to explore that version's code below.

About This Extension

Self-learning vector memory for AI agents — single-file .rvf cognitive container with HNSW search, episodic Reflexion memory, causal graph + Cypher, 9 RL algorithms, Thompson Sampling bandit, 41 MCP tools, hybrid (BM25 + dense) retrieval, GNN attention. 1

Frequently Asked Questions