MCP Registry

troxy-cli

176b5c59-e832-5974-bee5-ec86326e8b0a | v1.29.22
100/ 100
CRITICAL risk
No change since v1.29.21
Analyst verdict
Benign but powerful

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
Today
Version
v1.29.22
Artifact
SHA256 F57…8B6
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

15 detail rows

Finding Categories

12
Secrets
2
Network

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Security Analysis: troxy-cli

Tool Poisoning Assessment

No tool-poisoning findings detected. The findings summary shows "tool-poisoning":"0", which is critical because tool poisoning is the defining threat for MCP packages. There are no hidden AI manipulation directives, no XML-style instruction tags, and no evidence of tool descriptions containing covert commands aimed at AI agents. The package defines legitimate payment control functionality without embedding instructions to manipulate AI behavior.

Credential and Network Access

No credential theft architecture detected. The findings summary shows "secret":"0" with no credential-access findings targeting sensitive paths like .ssh/, .aws/credentials, .kube/config, or specific secret names (GITHUB_TOKEN, AWS_SECRET_ACCESS_KEY). The package reads configuration from src/config.js and handles authentication via src/auth.js, which is normal for an MCP server requiring API credentials.

Network activity is expected and limited. Two network findings exist:

  • NET-FETCH-src/api.js-10 - fetch call in API module
  • NET-FETCH-bin/troxy.js-241 - fetch call in CLI binary

These are generic fetch calls without suspicious domain indicators. For a payment control MCP server described as "protect your agent's payments with policies," API communication is expected behavior. No exfiltration domains or unknown endpoints are identified in the findings.

Malware and Obfuscation

Zero malware signatures and zero obfuscation findings. The findings summary shows "malware-signature":"0", "malware":"0", and "obfuscation":"0". The codebase does not exhibit steganographic patterns, zero-width Unicode characters, or minification-based obfuscation that would indicate hidden payloads.

Strongest Counterargument

The strongest argument against this verdict is the anonymous publisher (giladaslan) with zero users (user_count: 0). New MCP servers from unknown developers warrant scrutiny. However, the actual security findings are clean: no tool poisoning, no credential theft, no malware signatures. The package name "troxy" is a stylized spelling of "proxy" but does not match any well-known package for typosquatting. Without evidence of malicious behavior in the code, publisher anonymity alone does not justify a risk verdict.

Conclusion

The troxy-cli package presents no detectable security threats. All findings are consistent with legitimate MCP server behavior for payment control functionality. The absence of tool-poisoning, credential theft, and malware signatures supports a benign classification.

Key Reasons

  • Zero tool-poisoning findings (defining MCP threat absent)
  • Zero credential theft or secret access findings
  • Zero malware signatures or obfuscation
  • Network calls are expected for payment control API tool
  • Findings consistent with legitimate MCP server behavior

False Positive Considerations

  • Generic network fetch calls expected for API-based tools
  • Metadata hash identifiers are not security concerns

Reviewed 2026-05-08; recommended action: no action; model confidence 85%.

MCP version history

Risk trend by version

48 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
100
Change since first
+46
Change from previous
No change
Versions:
First analyzed version
1.2.3
Apr 26, 2026
Risk range
52 to 100
Across analyzed versions
Latest analyzed version
1.29.22
Oct 1, 2026
Selected version
critical
Version
v1.29.22
Today
Risk score
100
Findings
15
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

A secure control layer for AI agents: policies across payments, messages, logins, destructive actions, model usage, and secrets, all enforceable from the CLI

Frequently Asked Questions