MCP Registry

@kya-os/mcp-i-core

by h0bb5
25e4828f-3e17-5030-a716-9708be31e072 | v1.9.4
49/ 100
MEDIUM risk
No change since v1.9.3
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (49/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v1.9.4
Artifact
SHA256 31D…B0A
Source
Findings (non-IoC)

Is @kya-os/mcp-i-core safe?

The @kya-os/mcp-i-core package is a compatibility shim that re-exports runtime and W3C Verifiable Credentials delegation modules. It declares no special permissions or host permissions. The network endpoints it interacts with include standard identity infrastructure like w3id.org and schema.modelcontextprotocol-identity.io, which are expected for a library handling decentralized identifiers.

The scanner flagged a network fetch in dist/delegation/did-web-resolver.js and extracted 63 indicators of compromise. If these were real, they would mean the package is contacting unknown servers to exfiltrate data. However, the extracted domains include property access chains like date.now and app.post, alongside test placeholders like server1.com, which are artifacts of the code's test fixtures and URL parsing logic rather than actual external connections.

The 78 code-smell findings are low-severity noise that trigger on standard Node.js patterns in bundled files. With zero tool-poisoning patterns and no credential-access findings, the package is not stealing secrets or manipulating AI agents. The scanner tripped on the expected network calls of a DID resolver and the generic noise of bundled JavaScript.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1 detail row

Finding Categories

1
Network

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The package @kya-os/mcp-i-core is a compatibility shim that re-exports runtime and W3C Verifiable Credentials delegation modules, directing users to the product layer at @kya-os/mcp-i-runtime. When evaluating this package for tool poisoning, we find zero tool-poisoning findings. There are no hidden instructions, invisible Unicode characters, or XML-style tags embedded in tool descriptions aimed at manipulating an AI agent. This is expected for a library focused on cryptographic identity and delegation rather than AI tool orchestration.

Regarding credential scope, the evidence shows no credential-access findings. The package does not read sensitive paths like .ssh, .aws, or .kube, nor does it target specific environment variables like GITHUB_TOKEN or AWS_SECRET_ACCESS_KEY. There is no architecture present for harvesting secrets and exfiltrating them to an unknown domain. The package operates entirely within the bounds of a standard identity resolution library.

The network footprint consists of a single medium-severity finding, NET-FETCH-dist/delegation/did-web-resolver.js-73, which corresponds to a DID web resolver making HTTP requests. This is the expected behavior for a module resolving decentralized identifiers. The extracted network endpoints align with this purpose, including standard W3C and identity infrastructure like w3id.org, w3c-ccg.github.io, and schema.modelcontextprotocol-identity.io. The remaining endpoints are largely artifacts of the extraction process. Strings like app.post, date.now, and parsed.payload.vc are property access chains misidentified as domains by the IoC extractor. Entries like server1.com, server2.com, and issuer.com are placeholder domains typically found in test fixtures or documentation examples within W3C specification code.

The strongest counterargument to a clean verdict is the sheer volume of findings: 63 IoC matches and 78 code-smell hits. A high volume of alerts often warrants suspicion in the MCP ecosystem. However, the 78 code-smell findings are low-severity noise that trigger on standard Node.js patterns in bundled or minified JavaScript. The 63 IoC matches are entirely explained by the DID resolver's legitimate HTTP calls, combined with the extractor misidentifying JavaScript property chains and test placeholders as malicious infrastructure. There are zero malware signatures and zero secret findings.

Ultimately, this package is a benign compatibility shim. The scanner tripped on the expected network behavior of a decentralized identity resolver and the generic noise of bundled JavaScript. There is no evidence of credential theft, tool poisoning, or data exfiltration.

Key Reasons

  • Zero tool-poisoning findings and no hidden AI directives
  • No credential-access findings or sensitive path reads
  • Single network finding corresponds to legitimate DID web resolution
  • IoC matches are property access chains and test placeholders
  • Code-smell findings are low-severity noise from bundled JavaScript

False Positive Considerations

  • IoC extractor misidentifying property access chains as domains
  • Test placeholder domains in W3C specification code
  • Code-smell rules triggering on standard Node.js patterns in bundled JavaScript

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 92%.

MCP version history

Risk trend by version

7 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
49
Change since first
-10
Change from previous
No change
Versions:
First analyzed version
1.7.0
Apr 28, 2026
Risk range
44 to 59
Across analyzed versions
Latest analyzed version
1.9.4
Sep 29, 2026
Selected version
medium
Version
v1.9.4
2 days ago
Risk score
49
Findings
142
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Compatibility shim — re-exports @kya-os/mcp-i-runtime (product layer) plus the pinned W3C-VC delegation modules. Prefer @kya-os/mcp-i-runtime directly.

Frequently Asked Questions