@frontmcp/sdk
The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.
Analysis record
- Analysed
- Today
- Version
- v1.8.7
- Artifact
- SHA256 339…EE6
- Source
- Findings (non-IoC)
Is @frontmcp/sdk safe?
@frontmcp/sdk is the FrontMCP SDK, an MCP server package published at version 1.8.7. It declares no special permissions and lists no network endpoints in its metadata. The package bundles its dependencies into a single index.js file and an esm/index.mjs module, which is standard practice for JavaScript SDKs distributed on npm.
The scanner flagged 49 network fetch calls in the bundled index.js file and 12 hardcoded transport token references across the main module and TypeScript declaration files. The network fetch calls live at line numbers above 26000, which means they come from bundled third-party libraries rather than from code the FrontMCP authors wrote directly. No suspicious external domains were extracted from those calls. The hardcoded transport token findings, titled MCP-TRANSPORT-HARDCODED-TOKEN, point to the MCP stdio transport authentication layer, where a fixed token is used for session verification. That is a weak security practice because the token is visible in the source, but it is not the same thing as stealing credentials from your machine and sending them somewhere.
No tool-poisoning patterns matched this package. The scanner found zero hidden instructions aimed at an AI agent, zero invisible Unicode characters in tool descriptions, and zero XML-style directive tags in the metadata. The two obfuscation findings are function indirection patterns that TypeScript and bundlers produce automatically. None of the 67 findings describe behavior that steals data, manipulates AI responses, or communicates with unknown servers. The package is a standard bundled SDK with a lax transport configuration.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Finding Categories
MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The @frontmcp/sdk package is described as the FrontMCP SDK, published under the developer name GitHub Actions at version 1.8.7. We examined 67 findings across three categories: network calls, obfuscation patterns, and hardcoded transport tokens.
Zero tool-poisoning findings matched this package. The scanner found no hidden AI directives, no invisible Unicode instructions, and no XML-style tags embedded in tool metadata. For an MCP SDK, this is the clean result we want to see on the defining threat.
The 49 network findings all carry the title NET-FETCH and point to high line numbers in index.js (lines 26109 through 43964). Those line numbers tell the story: this is a bundled distribution file where dozens of dependencies are concatenated into a single module. Each bundled library that makes HTTP calls triggers its own NET-FETCH finding. No specific external domains were extracted by the IoC processor, and the network_endpoints array is empty. Without a suspicious destination to pair with these fetch calls, they remain unremarkable. SDK packages make network calls to their own APIs as a core function.
The 12 secret findings all share the title MCP-TRANSPORT-HARDCODED-TOKEN and appear in index.js, esm/index.mjs, and two TypeScript declaration files under common/metadata/. This finding targets the MCP stdio transport layer, where authentication tokens can be configured. A hardcoded token in transport configuration means the server uses a fixed credential for stdio session authentication rather than generating one dynamically. That is a weak security practice, because anyone who reads the source can see the token. It is not credential exfiltration. The code is not harvesting AWS keys, SSH private keys, or GitHub tokens from the environment and sending them to an external server. There are zero credential-access findings targeting .ssh, .aws, .kube, or any other sensitive path.
The two obfuscation findings carry the title OBFUSCATION-function_indirect and appear in index.js and esm/index.mjs. Function indirection is a standard artifact of TypeScript compilation and JavaScript bundling. Transpilers routinely rewrite direct function calls into indirect reference patterns. This is not steganography or intentional concealment.
The strongest argument against a clean bill of health is the hardcoded transport token itself. If an attacker controlled the FrontMCP infrastructure, they could use that token to impersonate the server in a stdio session. But that requires a separate compromise of the publisher build pipeline. The package as distributed does not exfiltrate credentials, inject instructions into AI agent conversations, or call unknown domains. The findings are artifacts of bundled code and a lax transport configuration.
Key Reasons
- Zero tool-poisoning findings across the entire package
- No IoC or suspicious external domains extracted from network calls
- NET-FETCH findings concentrated in bundled index.js at high line numbers indicating third-party library code
- MCP-TRANSPORT-HARDCODED-TOKEN findings target stdio transport auth configuration rather than credential harvesting
- No credential-access findings targeting .ssh, .aws, .kube, or other sensitive paths
False Positive Considerations
- Bundled dependencies in index.js generating multiplicative NET-FETCH findings at high line numbers
- MCP-TRANSPORT-HARDCODED-TOKEN matching stdio transport auth patterns rather than credential theft
- OBFUSCATION-function_indirect matching TypeScript compilation and bundler output artifacts
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 78%.
MCP version history
Risk trend by version
22 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace