From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- Yesterday
- Version
- v3.41.0
- Artifact
- SHA256 77E…B57
- Source
- Findings (non-IoC)
Is @stigmer/mcp-server safe?
@stigmer/mcp-server connects an AI agent to the Stigmer platform, exposing Stigmer agents, skills, workflows and other MCP servers as tools the model can call. It declares no manifest permissions and no host permissions, so it runs with whatever access the agent session already holds. The one network destination that lines up with the package's purpose, agentic.stigmer.ai, belongs to the vendor itself. Everything else in the endpoint list, from console.info to input.do, came from the scanner misreading JavaScript property chains as domain names.
Three findings labeled MCP-TOOL-TOOL-POISONING sit in cli/mcp-server-stigmer.js at lines 198 and 204. Tool poisoning means hidden instructions buried in a tool description that push the model toward something the user never asked for, like hiding an action or shipping data elsewhere. If those lines did that, this server could quietly steer your agent. The same file also triggered a large_base64 obfuscation hit, which on its own marks a chunk of encoded data, not a hidden payload.
The flagged file ships as a bundled CLI, and two of the three poisoning hits land on the same line, which points at a pattern match on tool registration code rather than a crafted instruction. Nothing here reads .ssh, .aws or other credential paths, and no call leaves the vendor's own domain. Read those two lines and the tool descriptions they define before adding this to an agent.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
14 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 21 | src/domains/environments/fetch.tsgen/mcpserver.jssrc/config.ts +18 more | - |
| LOW | postinstall persistence mechanism | 22 | domains/client.d.tssrc/domains/client.tssrc/readiness.ts +19 more | - |
| LOW | UsingCommandLineArguments | 3 | src/gen/mcpserver.tscli/mcp-server-stigmer.jsgen/mcpserver.js | - |
| LOW | postinstall file download | 76 | src/domains/agents/resources.tsdomains/agentexecutions/tools.jsdomains/workflows/tools.js +73 more | - |
| LOW | NoUseWeakRandom | 1 | cli/mcp-server-stigmer.js | - |
| LOW | HavingAPermissiveCrossOriginResourceSharingPolicy | 3 | server.jssrc/server.tscli/mcp-server-stigmer.js | - |
| LOW | SQLInjection | 2 | domains/environments/tools.jssrc/domains/environments/tools.ts | - |
| LOW | postinstall network communication | 68 | domains/conversation/calls.d.tssrc/domains/skills/delete.tsdomains/conversation/errors.js +65 more | - |
| LOW | postinstall crypto operations | 19 | src/domains/skills/versions.tssrc/domains/skills/resources.tscli/mcp-server-stigmer.js +16 more | - |
| LOW | postinstall file manipulation | 54 | domains/environments/delete.js.mapdomains/memory/errors.jsdomains/workflows/delete.js +51 more | - |
| LOW | postinstall system command | 68 | domains/memory/calls.jsdomains/workflowexecutions/run.js.mapsrc/config.ts +65 more | - |
| LOW | postinstall environment access | 9 | domains/environments/tools.d.tsconfig.d.tsgen/environment.d.ts +6 more | - |
| LOW | postinstall registry modification | 18 | domains/workflows/taskkinds.d.tsREADME.mdsrc/domains/channels/tools.ts +15 more | - |
| LOW | postinstall obfuscation | 12 | src/gen/mcpserver.tssrc/domains/workflows/validate.tsdomains/marshal.js +9 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
14 rules(376 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category tool poisoning; evidence quality moderate.
@stigmer/mcp-server v3.41.0 comes from publisher whysosuresh and wires Stigmer agents, skills, MCP servers and workflows into an AI agent as MCP tools and resources. The package name fits the vendor scope, and version 3.41.0 points at a mature release line rather than a fresh typosquat.
Tool poisoning. Three critical findings share one title pattern: MCP-TOOL-TOOL-POISONING-cli/mcp-server-stigmer.js-198, plus two more at line 204. This is the defining MCP threat, so it deserves the attention. What we can see points away from live hidden directives. The hits sit on two adjacent lines inside a bundled CLI file, exactly where tool registration code attaches descriptions to tool objects. Two identical findings on the same line normally mean one pattern matched twice, not two separate payloads. Nothing in the evidence shows directive text aimed at a model, such as "do not tell the user" or "ignore previous instructions". Verdict on this threat: unproven. A human needs to read lines 198 and 204 and judge the description strings.
Credentials and network. No credential-access findings at all. Nothing touches .ssh, .aws/credentials, .kube/config or application_default_credentials.json, and no secret findings matched. The four NET-FETCH hits sit in src/domains/resourcehandler.ts at lines 57 and 75, and in its build output domains/resourcehandler.js at lines 16 and 24. Resource handlers are a normal place for an MCP server to call the platform API. The one endpoint matching the package's stated purpose is agentic.stigmer.ai, the vendor's own service. The rest of the endpoint list, acme.com, console.info, input.do, cxt.it, cst.bom, idempotencylevel2.no, executiontarget2.cloud, reads as the IoC extractor splitting JavaScript property chains and protobuf identifiers into fake hostnames. No harvest-plus-exfil architecture appears anywhere in this package.
Obfuscation. OBFUSCATION-large_base64 fires on cli/mcp-server-stigmer.js. A large base64 string inside a shipped CLI bundle usually holds an embedded asset, and zero malware signatures matched across the whole package.
Severity context. Of 438 findings, 379 carry low severity and the code-smell label, the kind that match any non-trivial JavaScript referencing fetch, process.env or fs. Another 50 are IoC noise. Malware and secret counts are both zero.
The counterargument. The strongest case against my read: tool poisoning hides best, the scanner flagged three critical hits in a single file, and we cannot see the description strings ourselves. A hostile server would look identical at the metadata level. That does not change the conclusion. A vendor MCP server with no credential reads, no exfiltration destination and a first-party network target has a benign explanation for every finding, while the one genuinely unresolved item is a code read, not a behaviour we can infer from file paths alone.
Key Reasons
- Three critical MCP-TOOL-TOOL-POISONING hits cluster on two adjacent lines (198, 204) of the bundled CLI file, consistent with tool registration code rather than distinct payloads
- Zero credential-access findings: no .ssh, .aws/credentials, .kube/config or application_default_credentials.json reads
- Only network destination matching the package's purpose is agentic.stigmer.ai, the vendor's own service, with the remainder reading as IoC property-chain noise
- No malware signatures and no secret findings; 379 of 438 findings are low-severity code-smell hits on bundled JavaScript
- Tool descriptions themselves are not visible in the evidence, so the poisoning hits cannot be confirmed or dismissed without reading lines 198 and 204
False Positive Considerations
- IoC extractor splitting property chains and protobuf identifiers into fake hosts (console.info, input.do, cxt.it, idempotencylevel2.no)
- 379 low-severity code-smell hits typical of any bundled JavaScript
- Large base64 blob in a shipped CLI bundle flagged as obfuscation
- Duplicate tool-poisoning finding on the same line (204) indicating a repeated pattern match
Reviewed 2026-09-30; recommended action: reanalyze; model confidence 60%.
MCP version history
Risk trend by version
51 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace