The AI review rates the findings as likely false positive, but the risk score (49/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v1.9.4
- Artifact
- SHA256 31D…B0A
- Source
- Findings (non-IoC)
Is @kya-os/mcp-i-core safe?
The @kya-os/mcp-i-core package is a compatibility shim that re-exports runtime and W3C Verifiable Credentials delegation modules. It declares no special permissions or host permissions. The network endpoints it interacts with include standard identity infrastructure like w3id.org and schema.modelcontextprotocol-identity.io, which are expected for a library handling decentralized identifiers.
The scanner flagged a network fetch in dist/delegation/did-web-resolver.js and extracted 63 indicators of compromise. If these were real, they would mean the package is contacting unknown servers to exfiltrate data. However, the extracted domains include property access chains like date.now and app.post, alongside test placeholders like server1.com, which are artifacts of the code's test fixtures and URL parsing logic rather than actual external connections.
The 78 code-smell findings are low-severity noise that trigger on standard Node.js patterns in bundled files. With zero tool-poisoning patterns and no credential-access findings, the package is not stealing secrets or manipulating AI agents. The scanner tripped on the expected network calls of a DID resolver and the generic noise of bundled JavaScript.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Finding Categories
MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The package @kya-os/mcp-i-core is a compatibility shim that re-exports runtime and W3C Verifiable Credentials delegation modules, directing users to the product layer at @kya-os/mcp-i-runtime. When evaluating this package for tool poisoning, we find zero tool-poisoning findings. There are no hidden instructions, invisible Unicode characters, or XML-style tags embedded in tool descriptions aimed at manipulating an AI agent. This is expected for a library focused on cryptographic identity and delegation rather than AI tool orchestration.
Regarding credential scope, the evidence shows no credential-access findings. The package does not read sensitive paths like .ssh, .aws, or .kube, nor does it target specific environment variables like GITHUB_TOKEN or AWS_SECRET_ACCESS_KEY. There is no architecture present for harvesting secrets and exfiltrating them to an unknown domain. The package operates entirely within the bounds of a standard identity resolution library.
The network footprint consists of a single medium-severity finding, NET-FETCH-dist/delegation/did-web-resolver.js-73, which corresponds to a DID web resolver making HTTP requests. This is the expected behavior for a module resolving decentralized identifiers. The extracted network endpoints align with this purpose, including standard W3C and identity infrastructure like w3id.org, w3c-ccg.github.io, and schema.modelcontextprotocol-identity.io. The remaining endpoints are largely artifacts of the extraction process. Strings like app.post, date.now, and parsed.payload.vc are property access chains misidentified as domains by the IoC extractor. Entries like server1.com, server2.com, and issuer.com are placeholder domains typically found in test fixtures or documentation examples within W3C specification code.
The strongest counterargument to a clean verdict is the sheer volume of findings: 63 IoC matches and 78 code-smell hits. A high volume of alerts often warrants suspicion in the MCP ecosystem. However, the 78 code-smell findings are low-severity noise that trigger on standard Node.js patterns in bundled or minified JavaScript. The 63 IoC matches are entirely explained by the DID resolver's legitimate HTTP calls, combined with the extractor misidentifying JavaScript property chains and test placeholders as malicious infrastructure. There are zero malware signatures and zero secret findings.
Ultimately, this package is a benign compatibility shim. The scanner tripped on the expected network behavior of a decentralized identity resolver and the generic noise of bundled JavaScript. There is no evidence of credential theft, tool poisoning, or data exfiltration.
Key Reasons
- Zero tool-poisoning findings and no hidden AI directives
- No credential-access findings or sensitive path reads
- Single network finding corresponds to legitimate DID web resolution
- IoC matches are property access chains and test placeholders
- Code-smell findings are low-severity noise from bundled JavaScript
False Positive Considerations
- IoC extractor misidentifying property access chains as domains
- Test placeholder domains in W3C specification code
- Code-smell rules triggering on standard Node.js patterns in bundled JavaScript
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 92%.
MCP version history
Risk trend by version
7 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace