MCP Registry

metaharness

by ruvnet
1c9307b7-ca5c-559f-a86e-b03d019fa0a0 | v0.4.15
55/ 100
MEDIUM risk
No change since v0.4.12
Risk verdict
Review before use

Score-based assessment (medium risk, 55/100). No analyst review available.

Analysis record

Analysed
4 weeks ago
Version
v0.4.15
Artifact
SHA256 31A…21D
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

414 detail rows

YARA Rule Matches

12 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 23
dist/publish.jstemplates/vertical_research/.claude/settings.json.tmpldist/index.js +20 more
-
LOWUsingCommandLineArguments 1
dist/with-wasm.js
-
LOWpostinstall system command 233
templates/vertical_sales/src/agents/closer.ts.tmpldist/diag.d.tstemplates/vertical_gaming/bin/cli.js.tmpl +230 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 7
dist/learn.jsdist/secrets.jsdist/meta-proxy.js +4 more
-
LOWpostinstall obfuscation 24
dist/meta-proxy.d.tsdist/meta-proxy.jsdist/analyze-repo.js +21 more
-
LOWpostinstall network communication 4
dist/index.jsLICENSEdist/meta-proxy.js +1 more
-
LOWpostinstall crypto operations 19
dist/publish-cmd.jsdist/diag.jsdist/publish.d.ts +16 more
-
LOWpostinstall registry modification 11
dist/publish.jsdist/secrets.d.tsdist/registry.js.map +8 more
-
LOWpostinstall environment access 20
dist/manifest.d.tsdist/eject.d.tsdist/subcommands.d.ts +17 more
-
LOWpostinstall file manipulation 27
templates/vertical_devops/.claude/settings.json.tmpldist/meta-proxy.jsdist/analyze-repo.js +24 more
-
LOWcredential env files 33
dist/secrets.jstemplates/vertical_support/.claude/settings.json.tmpldist/publish-cmd.js +30 more
-
LOWpostinstall persistence mechanism 6
dist/meta-proxy-service.d.tsdist/meta-proxy-service.jsdist/meta-proxy.js +3 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

66 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

5
Network
66
IoC Indicators

YARA Rules Matched

12 rules(408 hits)
postinstall file download UsingCommandLineArguments postinstall system command UsingShellInterpreterWhenExecutingOSCommands postinstall obfuscation postinstall network communication postinstall crypto operations postinstall registry modification postinstall environment access postinstall file manipulation credential env files postinstall persistence mechanism

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

Security Analysis Summary

Security Analysis Overview

metaharness is a MCP Servers extension published by ruvnet. Version 0.4.15 has been analyzed by the Risky Plugins security platform, receiving a risk score of 55.35/100 (MEDIUM risk) based on 480 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • High: 1 finding(s)
  • Medium: 71 finding(s)
  • Low: 408 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

metaharness is published by ruvnet on the MCP Servers marketplace.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

MCP version history

Risk trend by version

6 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
55
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
0.4.4
Aug 11, 2026
Risk range
55 to 55
Across analyzed versions
Latest analyzed version
0.4.15
Sep 2, 2026
Selected version
medium
Version
v0.4.15
4 weeks ago
Risk score
55
Findings
480
Change vs previous
0

Pick any point on the chart to explore that version's code below.

About This Extension

MetaHarness — mint a custom AI agent harness from any repo. Browser Studio + `npx metaharness` CLI. Runs on Claude Code, Codex, pi.dev, Hermes, OpenClaw, RVM, Prime Agent.

Frequently Asked Questions