From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 1 months ago
- Version
- v3.0.0-alpha.20
- Artifact
- SHA256 4B5…3C9
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
14 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | NoUseEval | 2 | dist/src/db-fallback.d.tsdist/src/db-fallback.js | - |
| LOW | NoUseWeakRandom | 31 | dist/src/controllers/AttentionService.jsdist/src/cli/commands/route.jsdist/src/controllers/MincutService.js +28 more | - |
| LOW | postinstall file download | 15 | dist/src/controllers/ReflexionMemory.jsdist/src/model/ModelCacheLoader.d.tsdist/src/controllers/HNSWIndex.js +12 more | - |
| LOW | postinstall obfuscation | 49 | dist/src/cli/commands/route.jsdist/src/controllers/ExplainableRecall.d.tsdist/src/optimizations/Quantization.js +46 more | - |
| LOW | postinstall system command | 123 | dist/src/controllers/SparsificationService.jsdist/src/cli/lib/simulation-runner.d.tsdist/src/types/database.types.js +120 more | - |
| LOW | postinstall crypto operations | 33 | dist/src/cli/commands/doctor.jsdist/src/controllers/MincutService.d.tsdist/src/core/QueryCache.d.ts +30 more | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 1 | dist/src/cli/agentdb-cli.js | - |
| LOW | postinstall network communication | 48 | dist/src/backends/VectorBackend.d.tsdist/src/examples/quic-sync-example.jsLICENSE +45 more | - |
| LOW | postinstall file manipulation | 94 | dist/src/optimizations/Quantization.d.tsdist/src/cli/lib/report-generator.jsdist/src/utils/attention-metrics.js +91 more | - |
| LOW | postinstall registry modification | 15 | dist/src/cli/lib/simulation-registry.d.ts.mapdist/src/backends/rvf/SqlJsRvfBackend.d.tsdist/src/cli/lib/simulation-runner.js +12 more | - |
| LOW | postinstall environment access | 6 | dist/src/governance/RvfExperimentBranch.jsdist/src/backends/rvf/SelfLearningRvfBackend.jsdist/src/core/AgentDB.d.ts +3 more | - |
| LOW | UsingCommandLineArguments | 4 | dist/src/examples/quic-sync-example.jsdist/src/benchmark/BenchmarkSuite.jsdist/src/cli/agentdb-cli.js +1 more | - |
| LOW | credential env files | 17 | dist/src/services/LLMRouter.jsdist/src/services/LLMRouter.d.tsscripts/postinstall.cjs +14 more | - |
| LOW | postinstall persistence mechanism | 6 | dist/src/security/path-security.d.tsdist/src/services/AttentionService.jsdist/src/mcp/agentdb-mcp-server.js +3 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
14 rules(444 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category unknown malware; evidence quality weak.
AgentDB v3 presents a critical risk score primarily due to a massive volume of malware signature findings (476) and network indicators (785). The scanner detected 2 secret findings, 2 network activity findings, and 5 code-smell hits, but found zero instances of tool poisoning. In the MCP ecosystem, this pattern—high malware counts with zero tool poisoning—strongly suggests bundle contamination. The 476 malware signatures likely originate from minified JavaScript dependencies or utility libraries (e.g., specialized math/DB kernels) being misidentified by YARA rules. Similarly, the 785 IoCs are almost certainly the 'IPv6 fragment' or 'property chain' false positives typical of obfuscated code. However, the 'unknown' status of the findings forces a cautious stance: without verification, we cannot distinguish between aggressive false positives and a sophisticated supply-chain delivery (e.g., 'Gupti' malware) inside the dist bundle. The recommendation is manual review of the dist/ build artifacts or runtime sandboxing.
Key Reasons
- 476 malware signatures in dist/ likely false positives from minified deps
- Zero tool-poisoning findings despite high-risk classification
- High IoC count (785) consistent with property-access false positives
- Unknown findings preventing automated clearance
False Positive Considerations
- Minified/Bundled Dependencies
- Generic YARA Malware Signatures
- IPv6/Property-Access IoC Extraction Noise
Reviewed 2026-04-12; recommended action: reanalyze; model confidence 60%.
MCP version history
Risk trend by version
6 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace