MCP Registry

@kya-os/create-mcpi-app

by h0bb5
0fd1387d-797b-5365-81e5-74e65e5e52b9 | v1.12.1
100/ 100
CRITICAL risk
No change since v1.12.0
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v1.12.1
Artifact
SHA256 BA0…276
Source
Findings (non-IoC)

Is @kya-os/create-mcpi-app safe?

@kya-os/create-mcpi-app is a command-line tool that generates a starter MCP-I application. You run it once to scaffold a project, and it writes out a skeleton plus four bundled example apps. It declares no permissions and no host permissions, so it gets nothing from your browser or your agent at install time. The network addresses attached to it are claude.ai and app.anthropic.com, which are the expected destinations for MCP tooling.

The finding worth naming is a group of critical alerts titled MCP-TRANSPORT-HARDCODED-TOKEN, all of them inside bundled example files such as dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.js and dist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.js. If those were live credentials being sent somewhere, that would be serious. They sit in template code the generator copies into new projects, and nothing in the package calls an outside server with them.

The rest of the alert volume comes from the scanner reading minified bundle files. Strings like console.info, chunk.delta and binding.review are listed as network endpoints because they look like host names when a machine pulls them out of dense JavaScript. They are property names on objects. Nothing here reads your SSH keys, your AWS credentials or your kube config, and no hidden instructions target your AI agent.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

403 detail rows
Showing 25 of 213 · highest severity first

YARA Rule Matches

17 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall crypto operations 16
dist/bundles/mix-station.400dd62895aac28ae60f9e9dc4c344f287f4999327b2b10a9035621198fb8cae.jsdist/helpers/fetch-cloudflare-template.jsdist/helpers/wfp-bundle-options.js +13 more
-
LOWpostinstall file manipulation 16
dist/helpers/wrap/templates.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.jsdist/helpers/generate-identity.js +13 more
-
LOWpostinstall environment access 24
dist/helpers/validate-project-structure.jsdist/helpers/install.jsdist/utils/is-folder-empty.js +21 more
-
LOWAlertStatementsShouldNotBeUsed 4
dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.jsdist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.js +1 more
-
LOWpostinstall registry modification 11
dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.jsdist/helpers/wrap/templates.jsdist/helpers/get-package-versions.js +8 more
-
LOWpostinstall obfuscation 10
dist/helpers/validate-project-structure.d.tsdist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.jsdist/bundles/mix-station.400dd62895aac28ae60f9e9dc4c344f287f4999327b2b10a9035621198fb8cae.js +7 more
-
LOWpostinstall network communication 10
dist/helpers/fetch-cloudflare-template.jsdist/helpers/wrap/templates.d.tsdist/bundles/mix-station.400dd62895aac28ae60f9e9dc4c344f287f4999327b2b10a9035621198fb8cae.js +7 more
-
LOWpostinstall system command 17
dist/helpers/fetch-cloudflare-template.jsdist/helpers/fetch-mcpi-template.jsdist/bundles/mix-station.400dd62895aac28ae60f9e9dc4c344f287f4999327b2b10a9035621198fb8cae.js +14 more
-
LOWOriginsNotVerified 4
dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.jsdist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.js +1 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 3
dist/helpers/wrap/command.jsdist/helpers/fetch-xmcp-template.jsdist/helpers/install.js
-
LOWpostinstall file download 33
dist/helpers/fetch-cloudflare-mcpi-template.js.mapdist/utils/fetch-remote-config.d.tsdist/helpers/generate-cloudflare-files.js +30 more
-
LOWHavingAPermissiveCrossOriginResourceSharingPolicy 4
dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.jsdist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.js +1 more
-
LOWNoUseWeakRandom 4
dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.jsdist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.js +1 more
-
LOWNoExposeStackTrace 4
dist/bundles/mix-station.400dd62895aac28ae60f9e9dc4c344f287f4999327b2b10a9035621198fb8cae.jsdist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.js +1 more
-
LOWRedirectToUnknownPath 4
dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.jsdist/bundles/mix-station.400dd62895aac28ae60f9e9dc4c344f287f4999327b2b10a9035621198fb8cae.js +1 more
-
LOWcredential env files 20
dist/helpers/wrap/templates.jsdist/helpers/wrap/command.jsdist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.js +17 more
-
LOWpostinstall persistence mechanism 6
dist/helpers/fetch-cloudflare-mcpi-template.jsdist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.jsREADME.md +3 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

252 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

39
Secrets
157
Network
252
IoC Indicators

YARA Rules Matched

17 rules(190 hits)
postinstall crypto operations postinstall file manipulation postinstall environment access AlertStatementsShouldNotBeUsed postinstall registry modification postinstall obfuscation postinstall network communication postinstall system command OriginsNotVerified UsingShellInterpreterWhenExecutingOSCommands postinstall file download HavingAPermissiveCrossOriginResourceSharingPolicy NoUseWeakRandom NoExposeStackTrace RedirectToUnknownPath credential env files +1 more

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

What the package does

@kya-os/create-mcpi-app (version 1.12.1, published by h0bb5) is a scaffolding CLI. It writes a starter MCP-I project to disk and bundles four example apps under dist/bundles/ to show the shape of a finished project.

Tool poisoning

Nothing. The tool-poisoning bucket is empty, which matters most here. No tool description carries instructions aimed at an AI agent, no tool name hides invisible Unicode, and no metadata block wraps directives in XML tags. For an MCP-adjacent package that is the headline result, and it is negative.

Credential access

Thirty-nine findings carry the title MCP-TRANSPORT-HARDCODED-TOKEN, and each one lands in a bundled template: dist/bundles/blank.95bd4bbfb5f3fb70083ced77751677518931b0bff01a0fe9544fe3385f9d2e04.js (ten times), dist/bundles/ecommerce.ac9548d7ed449ef22996d1ad59be5e2be3a690c244ab0c911a4f634c36131290.js, dist/bundles/hardware-world.0b1b0776b93ec3e787ed65386a1e2af09cb30f99db84a9d310d259e97e3b842b.js, and dist/bundles/mix-station.400dd62895aac28ae60f9e9dc4c344f287f4999327b2b10a9035621198fb8cae.js. Those names map to the demo apps the generator emits. The transport rule looks for token-shaped strings in MCP client setup code, and template code is full of placeholder tokens for exactly that reason. Nothing reads ~/.ssh/id_rsa, ~/.aws/credentials, ~/.kube/config or application_default_credentials.json, and nothing enumerates AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN or OPENAI_API_KEY.

Network

The 157 network findings read as noise on inspection. The destination list holds console.info, chunk.delta, binding.review, action.pin, configuration.capabilities.delivery, and a markdown filename, 2026-07-29-consent-approve-auth-gate-design.md, lifted out of a docs file. These are property access chains the extractor split on a dot. The genuinely resolvable entries are claude.ai and app.anthropic.com, both of which are what an MCP scaffold is supposed to talk to. No POST goes to a host outside the package's purpose, so the harvest-then-exfiltrate shape is absent.

The strongest counterargument

Thirty-nine critical secrets is a lot of red on a scorecard, and the fair reading is that a generator shipping a hardcoded transport token in its template teaches every generated project to do the same. That is a hygiene problem worth an upstream issue. It is not exfiltration: no credential path is read, no unexpected host receives anything, and the 201 code-smell hits plus 252 IoC hits come from minified bundles rather than from behavior. Zero malware signatures, zero obfuscation findings, and empty permissions and host_permissions arrays round this out.

Key Reasons

  • Zero tool-poisoning findings: no hidden AI directives in any tool metadata
  • All 39 critical MCP-TRANSPORT-HARDCODED-TOKEN findings sit in bundled template apps under dist/bundles/ (blank, ecommerce, hardware-world, mix-station)
  • Network destinations are property chains (console.info, chunk.delta, codes.observer); the only real endpoints are claude.ai and app.anthropic.com
  • No reads of .ssh, .aws/credentials, .kube/config or application_default_credentials.json, and no targeted secret env names
  • No malware signatures, no obfuscation, no dependency findings; empty permissions and host_permissions

False Positive Considerations

  • Bundled dist/ template apps trigger IoC and code-smell rules at volume
  • IoC extractor splitting property access chains (console.info, chunk.delta) into fake domains
  • MCP transport hardcoded-token rule matching placeholder tokens in template code
  • Minified bundle JavaScript producing 201 code-smell hits unrelated to behavior

Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 72%.

MCP version history

Risk trend by version

13 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
100
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
1.9.35
Apr 23, 2026
Risk range
100 to 100
Across analyzed versions
Latest analyzed version
1.12.1
Sep 29, 2026
Selected version
critical
Version
v1.12.1
2 days ago
Risk score
100
Findings
655
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Scaffold a new MCP-I application

Frequently Asked Questions