MCP Registry

bring-mcp

2f9ceb85-9034-5f35-9d29-0d6438491d12 | v1.1.10
100/ 100
CRITICAL risk
No change since v1.1.9
Risk verdict
Do not install

Score-based assessment (critical risk, 100/100). Last analyst review covers version unknown.

Analysis record

Analysed
1 weeks ago
Version
v1.1.10
Artifact
SHA256 537…D3A
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

15 detail rows

Finding Categories

14
Secrets
1
Network

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

This MCP server presents a 'Critical' risk profile based on the scanner's output, but the underlying evidence suggests a false positive driven by noise in bundled dependencies. The package generated 82 findings, classified as 67 high severity and 12 IoC-related, yet zero findings for tool-poisoning, network exfiltration, or secrets.

The threat indicators show 27 'malware-signature' matches and 12 'IoC' matches without a single network request or tool-poisoning directive identified. This pattern is characteristic of YARA rules firing on minified JavaScript or common library code within the node_modules or dist folder of the package. The absence of network findings (NET-FETCH, NET-SOCKET_IO) combined with no secret or credential-access findings indicates there is no active exfiltration architecture or tool manipulation present.

In the context of MCP threat modeling, where tool poisoning and credential harvesting are the primary risks, the lack of any findings in those categories, despite a 'Critical' automated score, indicates this is a benign shopping list integration rather than a security threat. The 'bring-mcp' server appears to be a standard integration package inflated by scanner noise.

Key Reasons

  • No tool-poisoning findings detected despite critical risk score
  • 27 malware-signature findings with 0 network requests indicates bundled dependency noise
  • Zero secret or credential-access findings
  • High score (100) is a scanner artifact, not evidence of malicious behavior

False Positive Considerations

  • YARA rules firing on minified/bundled JavaScript in dist/
  • IoC extractor flagging generic library artifacts as threat indicators

Reviewed 2026-04-13; recommended action: suppress false positive; model confidence 85%.

MCP version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
100
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
1.1.9
Sep 3, 2026
Risk range
100 to 100
Across analyzed versions
Latest analyzed version
1.1.10
Sep 23, 2026
Selected version
critical
Version
v1.1.10
1 weeks ago
Risk score
100
Findings
15
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

MCP Server for Bring! Shopping

Frequently Asked Questions