MCP Registry

@stigmer/mcp-server

1201a53b-204d-58ff-990b-a61b62ec00ca | v3.41.0
77/ 100
HIGH risk
No change since v3.40.1
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
Yesterday
Version
v3.41.0
Artifact
SHA256 77E…B57
Source
Findings (non-IoC)

Is @stigmer/mcp-server safe?

@stigmer/mcp-server connects an AI agent to the Stigmer platform, exposing Stigmer agents, skills, workflows and other MCP servers as tools the model can call. It declares no manifest permissions and no host permissions, so it runs with whatever access the agent session already holds. The one network destination that lines up with the package's purpose, agentic.stigmer.ai, belongs to the vendor itself. Everything else in the endpoint list, from console.info to input.do, came from the scanner misreading JavaScript property chains as domain names.

Three findings labeled MCP-TOOL-TOOL-POISONING sit in cli/mcp-server-stigmer.js at lines 198 and 204. Tool poisoning means hidden instructions buried in a tool description that push the model toward something the user never asked for, like hiding an action or shipping data elsewhere. If those lines did that, this server could quietly steer your agent. The same file also triggered a large_base64 obfuscation hit, which on its own marks a chunk of encoded data, not a hidden payload.

The flagged file ships as a bundled CLI, and two of the three poisoning hits land on the same line, which points at a pattern match on tool registration code rather than a crafted instruction. Nothing here reads .ssh, .aws or other credential paths, and no call leaves the vendor's own domain. Read those two lines and the tool descriptions they define before adding this to an agent.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

388 detail rows

YARA Rule Matches

14 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 76
domains/workflows/resources.jsdomains/workflows/versions.d.tsdomains/environments/fetch.js.map +73 more
-
LOWNoUseWeakRandom 1
cli/mcp-server-stigmer.js
-
LOWHavingAPermissiveCrossOriginResourceSharingPolicy 3
src/server.tscli/mcp-server-stigmer.jsserver.js
-
LOWSQLInjection 2
domains/environments/tools.jssrc/domains/environments/tools.ts
-
LOWpostinstall network communication 68
domains/workflows/versions.jsdomains/environments/delete.jsdomains/channels/tools.js +65 more
-
LOWpostinstall crypto operations 19
src/domains/skills/resources.tscli/mcp-server-stigmer.jssrc/domains/workflows/tools.ts +16 more
-
LOWpostinstall file manipulation 54
domains/workflows/delete.d.tssrc/domains/skills/tools.tsserver.js +51 more
-
LOWpostinstall system command 68
src/domains/memory/context.tsdomains/workflowexecutions/tools.d.ts.mapdomains/memory/context.js +65 more
-
LOWpostinstall environment access 9
index.d.tsgen/workflow.d.tsdomains/environments/resources.d.ts +6 more
-
LOWpostinstall registry modification 18
domains/channels/tools.jssrc/gen/workflow.tsdomains/channels/errors.js +15 more
-
LOWpostinstall obfuscation 12
domains/workflows/taskkinds.jsgen/workflow.jssrc/domains/workflows/taskkinds.ts +9 more
-
LOWUsingCommandLineArguments 3
gen/mcpserver.jscli/mcp-server-stigmer.jssrc/gen/mcpserver.ts
-
LOWcredential env files 21
src/server.tssrc/domains/memory/context.tsserver.js +18 more
-
LOWpostinstall persistence mechanism 22
logger.d.tsdomains/memory/tools.d.tssrc/server.ts +19 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

50 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

1
Obfuscation
4
Network
50
IoC Indicators

YARA Rules Matched

14 rules(376 hits)
postinstall file download NoUseWeakRandom HavingAPermissiveCrossOriginResourceSharingPolicy SQLInjection postinstall network communication postinstall crypto operations postinstall file manipulation postinstall system command postinstall environment access postinstall registry modification postinstall obfuscation UsingCommandLineArguments credential env files postinstall persistence mechanism

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category tool poisoning; evidence quality moderate.

@stigmer/mcp-server v3.41.0 comes from publisher whysosuresh and wires Stigmer agents, skills, MCP servers and workflows into an AI agent as MCP tools and resources. The package name fits the vendor scope, and version 3.41.0 points at a mature release line rather than a fresh typosquat.

Tool poisoning. Three critical findings share one title pattern: MCP-TOOL-TOOL-POISONING-cli/mcp-server-stigmer.js-198, plus two more at line 204. This is the defining MCP threat, so it deserves the attention. What we can see points away from live hidden directives. The hits sit on two adjacent lines inside a bundled CLI file, exactly where tool registration code attaches descriptions to tool objects. Two identical findings on the same line normally mean one pattern matched twice, not two separate payloads. Nothing in the evidence shows directive text aimed at a model, such as "do not tell the user" or "ignore previous instructions". Verdict on this threat: unproven. A human needs to read lines 198 and 204 and judge the description strings.

Credentials and network. No credential-access findings at all. Nothing touches .ssh, .aws/credentials, .kube/config or application_default_credentials.json, and no secret findings matched. The four NET-FETCH hits sit in src/domains/resourcehandler.ts at lines 57 and 75, and in its build output domains/resourcehandler.js at lines 16 and 24. Resource handlers are a normal place for an MCP server to call the platform API. The one endpoint matching the package's stated purpose is agentic.stigmer.ai, the vendor's own service. The rest of the endpoint list, acme.com, console.info, input.do, cxt.it, cst.bom, idempotencylevel2.no, executiontarget2.cloud, reads as the IoC extractor splitting JavaScript property chains and protobuf identifiers into fake hostnames. No harvest-plus-exfil architecture appears anywhere in this package.

Obfuscation. OBFUSCATION-large_base64 fires on cli/mcp-server-stigmer.js. A large base64 string inside a shipped CLI bundle usually holds an embedded asset, and zero malware signatures matched across the whole package.

Severity context. Of 438 findings, 379 carry low severity and the code-smell label, the kind that match any non-trivial JavaScript referencing fetch, process.env or fs. Another 50 are IoC noise. Malware and secret counts are both zero.

The counterargument. The strongest case against my read: tool poisoning hides best, the scanner flagged three critical hits in a single file, and we cannot see the description strings ourselves. A hostile server would look identical at the metadata level. That does not change the conclusion. A vendor MCP server with no credential reads, no exfiltration destination and a first-party network target has a benign explanation for every finding, while the one genuinely unresolved item is a code read, not a behaviour we can infer from file paths alone.

Key Reasons

  • Three critical MCP-TOOL-TOOL-POISONING hits cluster on two adjacent lines (198, 204) of the bundled CLI file, consistent with tool registration code rather than distinct payloads
  • Zero credential-access findings: no .ssh, .aws/credentials, .kube/config or application_default_credentials.json reads
  • Only network destination matching the package's purpose is agentic.stigmer.ai, the vendor's own service, with the remainder reading as IoC property-chain noise
  • No malware signatures and no secret findings; 379 of 438 findings are low-severity code-smell hits on bundled JavaScript
  • Tool descriptions themselves are not visible in the evidence, so the poisoning hits cannot be confirmed or dismissed without reading lines 198 and 204

False Positive Considerations

  • IoC extractor splitting property chains and protobuf identifiers into fake hosts (console.info, input.do, cxt.it, idempotencylevel2.no)
  • 379 low-severity code-smell hits typical of any bundled JavaScript
  • Large base64 blob in a shipped CLI bundle flagged as obfuscation
  • Duplicate tool-poisoning finding on the same line (204) indicating a repeated pattern match

Reviewed 2026-09-30; recommended action: reanalyze; model confidence 60%.

MCP version history

Risk trend by version

51 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
77
Change since first
-15
Change from previous
No change
Versions:
First analyzed version
3.0.8
Jun 15, 2026
Risk range
73 to 92
Across analyzed versions
Latest analyzed version
3.41.0
Sep 30, 2026
Selected version
high
Version
v3.41.0
Yesterday
Risk score
77
Findings
438
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Model Context Protocol server for the Stigmer platform — exposes Stigmer agents, skills, MCP servers, and workflows as MCP tools and resources

Frequently Asked Questions