MCP Registry

@skillsmith/mcp-server

2c723c39-a20d-5587-b306-f7bcd5a37ce8 | v0.7.18
100/ 100
CRITICAL risk
No change since v0.7.17
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.

Analysis record

Analysed
Yesterday
Version
v0.7.18
Artifact
SHA256 4E6…90A
Source
Findings (non-IoC)

Is @skillsmith/mcp-server safe?

@skillsmith/mcp-server calls itself a registry for sharing, scanning, and tracking agent skills across teams. Its manifest asks for nothing: no host permissions, no permission strings, no listed network endpoints. That leaves a small surface. An agent loads the server as a tool provider and nothing more.

The scanner's loudest hits land on test fixtures. Thirty-five critical alerts carry the title MCP-TRANSPORT-HARDCODED-TOKEN, and every one points into a file such as dist/src/tools/team-resolver.test.js or dist/tests/unit/apply-manifest-reconcile.test.js. Those files exist to prove the server rejects bad credentials, so sample tokens sit inside them by design. A live production key shipped in a source file would matter. A placeholder inside shutdown.test.js goes nowhere and grants nobody access.

Thirty-five network alerts round out the count, though the record names no destination domain for any of them, and the package declares no endpoints of its own. Nothing in the scan matches a tool description that orders an AI around, hides instructions in Unicode, or reaches for .ssh or .aws credentials. The two categories that would worry us most, hidden AI directives and exfiltration to an unknown host, both come back empty.

The publisher field reads "GitHub Actions", which looks like a CI identity rather than a person, and that explains the odd wording on its own. Everything the scanner flagged traces to deliberate test data or to runtime scaffolding. The alerts describe how the scanner reads test files, not anything this package does to your machine.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

74 detail rows
Showing 25 of 74 · highest severity first

Finding Categories

35
Secrets
35
Network

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

What this package does

@skillsmith/mcp-server describes itself as a registry for sharing, scanning, and tracking agent skills across teams. Version 0.7.18 ships a compiled dist/ tree next to its source. The manifest declares no host permissions and no permission strings, and the package lists no network endpoints.

Tool poisoning

Zero tool-poisoning findings matched. No tool description in the package carries directives aimed at an AI agent. Nothing tells a model to stay silent, skip user confirmation, or run a command before replying. The tool names that do show up (team-workspace, team-resolver, registry-tools) read as ordinary registry operations. MCP servers legitimately contain description: fields, and scanners sometimes mistake those definitions for poisoning. Here nothing matched at all, so the question does not arise.

Credential and network findings

The heaviest cluster is 35 critical MCP-TRANSPORT-HARDCODED-TOKEN alerts. Every one lands in a .test.js file:

  • dist/tests/unit/namespace-audit-telemetry.test.js
  • dist/src/shutdown.test.js
  • dist/src/tools/team-workspace.test.js
  • dist/src/tools/team-resolver.test.js (six hits)
  • dist/tests/unit/apply-manifest-reconcile.test.js
  • dist/src/tools/registry-tools.team.test.js
  • dist/src/tools/registry-tools.live.manage.test.js

No production file, no server entry point, no tool implementation turns up in that list. Test suites for an authenticated MCP server need literal token strings to assert that bad credentials get rejected. The scanner matched those fixtures.

The other 35 findings sit in the network category, with no destination domain recorded and no endpoint attributed to the package. Nothing ties a credential read to a call to an unfamiliar host. The exfiltration shape, reading .ssh, .aws/credentials or .kube/config and then posting the contents somewhere, shows up nowhere here: no credential-access rule fires on those paths, and the scan records zero IoC and zero malware-signature matches.

Counterargument

The strongest case against this reading: 35 critical secrets is a lot, and the publisher string "GitHub Actions" names a CI job rather than a person or org, which makes attribution hard. A package that ships tokens inside dist/ could be leaking a real one. That argument fails on file placement. Hardcoded production credentials would live in the runtime code that talks to the registry, not exclusively in files whose names end in .test.js, and the scanner found none outside those files. The CI publisher string fits a repo that publishes from GitHub Actions, which is how most npm packages ship.

Verdict

The findings describe test fixtures and unspecified network calls, not hidden AI instructions or credential theft. Nothing here justifies concern beyond the ordinary caution that applies to any MCP server pointed at a development environment.

Key Reasons

  • All 35 critical MCP-TRANSPORT-HARDCODED-TOKEN findings land in .test.js fixtures (dist/src/tools/team-resolver.test.js, dist/tests/unit/apply-manifest-reconcile.test.js), with zero hits in runtime code
  • Zero tool-poisoning findings: no tool description carries directives aimed at an AI agent
  • The 35 network findings name no destination domain and the package declares no network endpoints
  • No credential-access rule fires on .ssh, .aws or .kube paths, and the scan records zero IoC and zero malware-signature matches
  • Publisher string 'GitHub Actions' fits a repo publishing from CI, and the manifest requests no permissions

False Positive Considerations

  • MCP-TRANSPORT-HARDCODED-TOKEN rule matching deliberate credential placeholders in test suites
  • Network findings with no destination domain attributed
  • dist/ tree containing compiled test files alongside bundled code
  • CI-generated publisher metadata read as an anonymous identity

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 72%.

MCP version history

Risk trend by version

18 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
100
Change since first
+6
Change from previous
No change
Versions:
First analyzed version
0.4.12
Apr 20, 2026
Risk range
94 to 100
Across analyzed versions
Latest analyzed version
0.7.18
Sep 30, 2026
Selected version
critical
Version
v0.7.18
Yesterday
Risk score
100
Findings
74
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

A registry for sharing, scanning, and tracking agent skills across teams.

Frequently Asked Questions