Based on the RiskyPlugins AI security review of the observed evidence.
No individual score drivers were recorded for this analysis.
Analysis record
- Analysed
- 6 months ago
- Version
- v0.1.4
- Artifact
- SHA256 178…80B
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Tool Poisoning Assessment
The findings summary shows "tool-poisoning":"0" — zero tool-poisoning findings were detected. This is a critical indicator that no hidden AI manipulation directives exist in this package. The code-smell findings (YARA--postinstall_file_manipulation and YARA--postinstall_network_communication in /tmp/extract-178087d461a97c933ba18dfb0af028fc32eaff3d776c0a83ae3c38a392cef80b-3709846637/package/dist/nodes/ViaCep/ViaCep.node.js) are low-severity YARA matches on basic Node.js patterns and are documented false positives per the CVEQ guidelines. These rules fire on almost any non-trivial JavaScript and should never drive a verdict.
Credential and Network Access
No credential-access findings, secret findings, or network findings exist in this bundle. The package reads no sensitive paths (.ssh, .aws, .kube, credentials files) and contains no exfiltration architecture. The IoC findings are all legitimate and expected for this package's stated purpose:
XIOC-DOMAIN-viacep.com.brandXIOC-URL-https://viacep.com.br/ws/$— The package description states it queries ViaCEP (Brazilian postal code lookup service). These are the legitimate API endpoints the package is designed to call.XIOC-DOMAIN-github.comandXIOC-URL-https://github.com/Marcosnb/viacep-n8n.git— Source repository reference.XIOC-DOMAIN-www.w3.org— Standard XML namespace reference.[email protected]andXIOC-DOMAIN-gmail.com— Developer contact information.
None of these domains represent suspicious exfiltration destinations. The package does not combine credential reads with network calls to unknown domains.
Strongest Counterargument
The 9 medium-severity IoC findings could suggest suspicious network activity. However, every single IoC is explainable: viacep.com.br is the documented service the package queries, github.com hosts the source code, and w3.org is a standard namespace. The package description explicitly states it queries ViaCEP for CEP (postal code) lookups, making these network destinations expected and legitimate. No IoC represents an unknown or suspicious domain.
Conclusion
This n8n node performs a single, well-defined function: querying the ViaCEP API for Brazilian postal code data. All findings are either documented false positives (code-smell YARA rules) or legitimate functionality (expected API calls to viacep.com.br). There is no evidence of tool poisoning, credential theft, exfiltration, or any malicious behavior.
Key Reasons
- Zero tool-poisoning findings detected
- All IoC findings are legitimate (viacep.com.br is the documented API the package queries)
- Code-smell findings are documented false positives (YARA rules on basic Node.js patterns)
- No credential-access or exfiltration architecture present
- Package purpose (CEP lookup via ViaCEP) matches all network destinations
False Positive Considerations
- YARA code-smell rules firing on basic Node.js patterns in dist/ files
- IoC findings for legitimate API endpoint (viacep.com.br) that matches package purpose
- No tool-poisoning findings detected
- No credential-access or secret findings
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace