The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v1.12.1
- Artifact
- SHA256 BA0…276
- Source
- Findings (non-IoC)
Is @kya-os/create-mcpi-app safe?
@kya-os/create-mcpi-app is a command-line tool that generates a starter MCP-I application. You run it once to scaffold a project, and it writes out a skeleton plus four bundled example apps. It declares no permissions and no host permissions, so it gets nothing from your browser or your agent at install time. The network addresses attached to it are claude.ai and app.anthropic.com, which are the expected destinations for MCP tooling.
The finding worth naming is a group of critical alerts titled MCP-TRANSPORT-HARDCODED-TOKEN, all of them inside bundled example files such as dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.js and dist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.js. If those were live credentials being sent somewhere, that would be serious. They sit in template code the generator copies into new projects, and nothing in the package calls an outside server with them.
The rest of the alert volume comes from the scanner reading minified bundle files. Strings like console.info, chunk.delta and binding.review are listed as network endpoints because they look like host names when a machine pulls them out of dense JavaScript. They are property names on objects. Nothing here reads your SSH keys, your AWS credentials or your kube config, and no hidden instructions target your AI agent.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
17 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall crypto operations | 16 | dist/bundles/mix-station.400dd62895aac28ae60f9e9dc4c344f287f4999327b2b10a9035621198fb8cae.jsdist/helpers/fetch-cloudflare-template.jsdist/helpers/wfp-bundle-options.js +13 more | - |
| LOW | postinstall file manipulation | 16 | dist/helpers/wrap/templates.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.jsdist/helpers/generate-identity.js +13 more | - |
| LOW | postinstall environment access | 24 | dist/helpers/validate-project-structure.jsdist/helpers/install.jsdist/utils/is-folder-empty.js +21 more | - |
| LOW | AlertStatementsShouldNotBeUsed | 4 | dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.jsdist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.js +1 more | - |
| LOW | postinstall registry modification | 11 | dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.jsdist/helpers/wrap/templates.jsdist/helpers/get-package-versions.js +8 more | - |
| LOW | postinstall obfuscation | 10 | dist/helpers/validate-project-structure.d.tsdist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.jsdist/bundles/mix-station.400dd62895aac28ae60f9e9dc4c344f287f4999327b2b10a9035621198fb8cae.js +7 more | - |
| LOW | postinstall network communication | 10 | dist/helpers/fetch-cloudflare-template.jsdist/helpers/wrap/templates.d.tsdist/bundles/mix-station.400dd62895aac28ae60f9e9dc4c344f287f4999327b2b10a9035621198fb8cae.js +7 more | - |
| LOW | postinstall system command | 17 | dist/helpers/fetch-cloudflare-template.jsdist/helpers/fetch-mcpi-template.jsdist/bundles/mix-station.400dd62895aac28ae60f9e9dc4c344f287f4999327b2b10a9035621198fb8cae.js +14 more | - |
| LOW | OriginsNotVerified | 4 | dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.jsdist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.js +1 more | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 3 | dist/helpers/wrap/command.jsdist/helpers/fetch-xmcp-template.jsdist/helpers/install.js | - |
| LOW | postinstall file download | 33 | dist/helpers/fetch-cloudflare-mcpi-template.js.mapdist/utils/fetch-remote-config.d.tsdist/helpers/generate-cloudflare-files.js +30 more | - |
| LOW | HavingAPermissiveCrossOriginResourceSharingPolicy | 4 | dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.jsdist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.js +1 more | - |
| LOW | NoUseWeakRandom | 4 | dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.jsdist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.js +1 more | - |
| LOW | NoExposeStackTrace | 4 | dist/bundles/mix-station.400dd62895aac28ae60f9e9dc4c344f287f4999327b2b10a9035621198fb8cae.jsdist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.js +1 more | - |
| LOW | RedirectToUnknownPath | 4 | dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.jsdist/bundles/mix-station.400dd62895aac28ae60f9e9dc4c344f287f4999327b2b10a9035621198fb8cae.js +1 more | - |
| LOW | credential env files | 20 | dist/helpers/wrap/templates.jsdist/helpers/wrap/command.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.js +17 more | - |
| LOW | postinstall persistence mechanism | 6 | dist/helpers/fetch-cloudflare-mcpi-template.jsdist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.jsREADME.md +3 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
17 rules(190 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
What the package does
@kya-os/create-mcpi-app (version 1.12.1, published by h0bb5) is a scaffolding CLI. It writes a starter MCP-I project to disk and bundles four example apps under dist/bundles/ to show the shape of a finished project.
Tool poisoning
Nothing. The tool-poisoning bucket is empty, which matters most here. No tool description carries instructions aimed at an AI agent, no tool name hides invisible Unicode, and no metadata block wraps directives in XML tags. For an MCP-adjacent package that is the headline result, and it is negative.
Credential access
Thirty-nine findings carry the title MCP-TRANSPORT-HARDCODED-TOKEN, and each one lands in a bundled template: dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.js (ten times), dist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.js, dist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.js, and dist/bundles/mix-station.400dd62895aac28ae60f9e9dc4c344f287f4999327b2b10a9035621198fb8cae.js. Those names map to the demo apps the generator emits. The transport rule looks for token-shaped strings in MCP client setup code, and template code is full of placeholder tokens for exactly that reason. Nothing reads ~/.ssh/id_rsa, ~/.aws/credentials, ~/.kube/config or application_default_credentials.json, and nothing enumerates AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN or OPENAI_API_KEY.
Network
The 157 network findings read as noise on inspection. The destination list holds console.info, chunk.delta, binding.review, action.pin, configuration.capabilities.delivery, and a markdown filename, 2026-07-29-consent-approve-auth-gate-design.md, lifted out of a docs file. These are property access chains the extractor split on a dot. The genuinely resolvable entries are claude.ai and app.anthropic.com, both of which are what an MCP scaffold is supposed to talk to. No POST goes to a host outside the package's purpose, so the harvest-then-exfiltrate shape is absent.
The strongest counterargument
Thirty-nine critical secrets is a lot of red on a scorecard, and the fair reading is that a generator shipping a hardcoded transport token in its template teaches every generated project to do the same. That is a hygiene problem worth an upstream issue. It is not exfiltration: no credential path is read, no unexpected host receives anything, and the 201 code-smell hits plus 252 IoC hits come from minified bundles rather than from behavior. Zero malware signatures, zero obfuscation findings, and empty permissions and host_permissions arrays round this out.
Key Reasons
- Zero tool-poisoning findings: no hidden AI directives in any tool metadata
- All 39 critical MCP-TRANSPORT-HARDCODED-TOKEN findings sit in bundled template apps under dist/bundles/ (blank, ecommerce, hardware-world, mix-station)
- Network destinations are property chains (console.info, chunk.delta, codes.observer); the only real endpoints are claude.ai and app.anthropic.com
- No reads of .ssh, .aws/credentials, .kube/config or application_default_credentials.json, and no targeted secret env names
- No malware signatures, no obfuscation, no dependency findings; empty permissions and host_permissions
False Positive Considerations
- Bundled dist/ template apps trigger IoC and code-smell rules at volume
- IoC extractor splitting property access chains (console.info, chunk.delta) into fake domains
- MCP transport hardcoded-token rule matching placeholder tokens in template code
- Minified bundle JavaScript producing 201 code-smell hits unrelated to behavior
Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 72%.
MCP version history
Risk trend by version
13 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace