MCP Registry

openregister-mcp

2d545534-afe0-56bb-a326-e38f51713652 | v4.8.2
100/ 100
CRITICAL risk
No change since v4.8.0
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.

Analysis record

Analysed
2 weeks ago
Version
v4.8.2
Artifact
SHA256 F84…ED9
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

199 detail rows

YARA Rule Matches

11 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 15
src/local-docs-search.tsoptions.jscode-tool.mjs +12 more
-
LOWpostinstall file download 29
code-tool-worker.d.mtshttp.mjsindex.mjs +26 more
-
LOWNoUseEval 3
code-tool-worker.jssrc/code-tool-worker.tscode-tool-worker.mjs
-
LOWUsingCommandLineArguments 1
src/options.ts
-
LOWpostinstall crypto operations 6
http.mjslocal-docs-search.jssrc/http.ts +3 more
-
LOWpostinstall obfuscation 25
code-tool-worker.mjscode-tool.jssrc/options.ts +22 more
-
LOWpostinstall file manipulation 25
src/http.tslocal-docs-search.jsinstructions.js +22 more
-
LOWpostinstall environment access 15
stdio.mjsoptions.d.mtsserver.d.ts +12 more
-
LOWpostinstall system command 32
code-tool.d.tscode-tool.jsserver.mjs +29 more
-
LOWpostinstall network communication 21
stdio.mjslocal-docs-search.jsindex.js +18 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 3
code-tool.jssrc/code-tool.tscode-tool.mjs
-

Finding Categories

12
Secrets
10
Network

YARA Rules Matched

11 rules(175 hits)
credential env files postinstall file download NoUseEval UsingCommandLineArguments postinstall crypto operations postinstall obfuscation postinstall file manipulation postinstall environment access postinstall system command postinstall network communication UsingShellInterpreterWhenExecutingOSCommands

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

This MCP server for the Openregister API presents a 'CRITICAL' risk score of 100 due to high-volume findings from bundled dependencies, but core threat indicators are absent. There are 0 tool-poisoning findings, 0 secret/access-token findings, and 0 network threats flagged in the summary. The 172 IoC and 110 malware-signature findings are characteristic of the 'Bundled Dependencies' false-positive pattern, where minified vendor code in dist/ or node_modules/ triggers YARA rules and hex-string IoCs (e.g., IPv6 fragments like ::, misread property chains). The lack of tool-poisoning is the strongest signal of safety: this package defines tools rather than attempting to manipulate the AI agent via hidden descriptions.

For a developer, this package represents a standard API client. The credential scope is likely limited to the standard OPENREGISTER_API_KEY or similar environment variables required for API authentication (confirmed by the 'official' description), though no specific secret harvesting was flagged. The network destinations are presumably the official Openregister API endpoints; the lack of network findings suggests no suspicious C2 domains.

Key Reasons

  • Zero tool-poisoning findings detected despite high risk score
  • Findings concentrated in IoC (172) and Malware-signature (110) categories typical of bundled dependencies
  • No secret or credential-access findings flagged
  • Package claims to be the official server for Openregister API

False Positive Considerations

  • High IoC count (172) likely from minified bundled JS code
  • Malware-signature hits (110) matching generic code patterns in vendor libraries
  • Risk score inflation from dependency noise rather than actual threats

Reviewed 2026-04-13; recommended action: suppress false positive; model confidence 85%.

MCP version history

Risk trend by version

14 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
100
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
4.3.0
Apr 21, 2026
Risk range
70 to 100
Across analyzed versions
Latest analyzed version
4.8.2
Sep 17, 2026
Selected version
critical
Version
v4.8.2
2 weeks ago
Risk score
100
Findings
199
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

The official MCP Server for the Openregister API

Frequently Asked Questions