Based on the RiskyPlugins AI security review of the observed evidence.
No individual score drivers were recorded for this analysis.
Analysis record
- Analysed
- 3 months ago
- Version
- v1.1.0
- Artifact
- SHA256 633…866
- Source
- Findings (non-IoC)
No Findings
All security checks passed
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Tool Poisoning Assessment
The evidence bundle contains zero tool-poisoning findings. This is the most significant finding because tool poisoning is the defining threat for MCP servers. The findings_summary explicitly shows "tool-poisoning":"0". There are no hidden AI directives, no XML-style instruction tags, and no Unicode steganography detected in tool descriptions.
Credential and Network Access
No credential-access findings exist in this package. The findings_summary shows "secret":"0" and "network":"0". The package does not read sensitive paths like .ssh/, .aws/, .kube/config, or target specific secret names like GITHUB_TOKEN or AWS_SECRET_ACCESS_KEY.
The IoC findings reference only legitimate, expected domains:
github.comandn8n.io- the package's hosting and platform domainswww.w3.org- standard web standards organization (SVG namespace)[email protected]- official n8n community email
All URLs point to the package's own GitHub repository at https://github.com/n8n-community/n8n-nodes-message-display. This is not exfiltration architecture; it's documentation and repository metadata.
Code-Smell Findings Analysis
The four code-smell findings are all severity: low and match documented false-positive patterns:
YARA--postinstall_system_commandin/package/README.md- This fires on documentation text, not executable codeYARA--postinstall_network_communicationin/package/dist/MessageDisplay.node.js- Bundled/minified JavaScript triggering basic Node.js pattern matchesYARA--postinstall_system_commandin/package/dist/MessageDisplay.node.js- Same bundled fileYARA--postinstall_system_commandin/package/dist/MessageDisplay.node.d.ts- TypeScript declaration file
These postinstall_* rules are classified as code-smell noise per the CVEQ false-positive documentation. They match basic patterns like fetch, exec, fs, and process.env that appear in almost any non-trivial JavaScript. The findings in dist/ files are expected because bundled dependencies trigger multiplicative false positives.
Strongest Counterargument
A skeptic might argue the developer name "marcos345" is anonymous and the package has 12 total findings. However, the package is hosted under the official n8n-community GitHub organization, which provides publisher verification. Finding counts are meaningless when all findings are benign IoCs and low-severity code-smell matches. The IoC count of 8 would be concerning if the domains were suspicious, but all domains are legitimate infrastructure (github.com, n8n.io, w3.org).
Conclusion
This n8n community node shows no evidence of malicious behavior. All findings are documented false-positive patterns: code-smell YARA rules on bundled code and IoC extraction of legitimate domains. The package performs its stated function (displaying messages in workflows) without credential harvesting, tool poisoning, or suspicious network activity.
Key Reasons
- Zero tool-poisoning findings (the defining MCP threat)
- All IoCs reference legitimate domains (github.com, n8n.io, w3.org)
- All code-smell findings are low-severity YARA matches on bundled code
- Package hosted on official n8n community GitHub organization
- No credential access or suspicious network activity detected
False Positive Considerations
- Code-smell YARA rules matching bundled/minified JavaScript
- IoC extraction of legitimate domains (github.com, n8n.io, w3.org)
- postinstall_* rules matching basic Node.js patterns
- Bundled dist/ files triggering multiplicative false positives
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 88%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace