bring-mcp
Score-based assessment (critical risk, 100/100). Last analyst review covers version unknown.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v1.1.10
- Artifact
- SHA256 537…D3A
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Finding Categories
MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality weak.
This MCP server presents a 'Critical' risk profile based on the scanner's output, but the underlying evidence suggests a false positive driven by noise in bundled dependencies. The package generated 82 findings, classified as 67 high severity and 12 IoC-related, yet zero findings for tool-poisoning, network exfiltration, or secrets.
The threat indicators show 27 'malware-signature' matches and 12 'IoC' matches without a single network request or tool-poisoning directive identified. This pattern is characteristic of YARA rules firing on minified JavaScript or common library code within the node_modules or dist folder of the package. The absence of network findings (NET-FETCH, NET-SOCKET_IO) combined with no secret or credential-access findings indicates there is no active exfiltration architecture or tool manipulation present.
In the context of MCP threat modeling, where tool poisoning and credential harvesting are the primary risks, the lack of any findings in those categories, despite a 'Critical' automated score, indicates this is a benign shopping list integration rather than a security threat. The 'bring-mcp' server appears to be a standard integration package inflated by scanner noise.
Key Reasons
- No tool-poisoning findings detected despite critical risk score
- 27 malware-signature findings with 0 network requests indicates bundled dependency noise
- Zero secret or credential-access findings
- High score (100) is a scanner artifact, not evidence of malicious behavior
False Positive Considerations
- YARA rules firing on minified/bundled JavaScript in dist/
- IoC extractor flagging generic library artifacts as threat indicators
Reviewed 2026-04-13; recommended action: suppress false positive; model confidence 85%.
MCP version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace