The AI review rates the findings as likely false positive, but the risk score (54/100) still counts them.
Analysis record
- Analysed
- 3 days ago
- Version
- v3.0.0
- Artifact
- SHA256 655…AEE
- Source
- Findings (non-IoC)
Is @claude-flow/mcp safe?
@claude-flow/mcp is a Model Context Protocol server that runs alongside an AI agent and gives it a standard way to reach tools, with stdio, HTTP and WebSocket transports, connection pooling and a tool registry. It declares no browser or host permissions. The addresses it talks to are api.anthropic.com for model traffic, modelcontextprotocol.io and spec.modelcontextprotocol.io for the protocol specification, and opensource.org and img.shields.io for license and badge links.
The findings worth naming come from three network calls: NET-FETCH-dist/oauth.js-99 and NET-FETCH-dist/oauth.js-134 in dist/oauth.js, and NET-FETCH-dist/sampling.js-231 in dist/sampling.js. Those files handle OAuth sign-in and MCP sampling, and both features are built around making an HTTP request, so a fetch there is the function doing its job. No finding reads .ssh, .aws or .kube files, and no address sits outside the package's own purpose.
The rest of the scan result is scanner noise. Most of it is low-severity code-smell rules that match any compiled JavaScript, plus a set of indicators pulled from the built files in dist/, where one minified line can be counted several times. That describes the shape of bundled output rather than behaviour.
If you are deciding whether to add this to an agent, the thing to know is that it is a framework with broad reach: it can pass tool calls, hold connections open and talk to a model endpoint. That reach is the point of it, and nothing in this scan shows it used for anything else.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
11 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall crypto operations | 2 | dist/transport/http.jsdist/oauth.js | - |
| LOW | postinstall system command | 11 | dist/task-manager.d.tsdist/tool-registry.jsREADME.md +8 more | - |
| LOW | postinstall file manipulation | 16 | dist/connection-pool.jsdist/oauth.d.tsdist/task-manager.js +13 more | - |
| LOW | DisablingContentSecurityPolicyFetchDirectives | 1 | dist/transport/http.js | - |
| LOW | postinstall registry modification | 18 | dist/resource-registry.js.mappackage.jsondist/server.js +15 more | - |
| LOW | postinstall network communication | 27 | dist/index.jsdist/connection-pool.jsdist/session-manager.js +24 more | - |
| LOW | postinstall obfuscation | 11 | dist/prompt-registry.d.tsdist/schema-validator.jsdist/schema-validator.d.ts +8 more | - |
| LOW | NoUseEval | 1 | README.md | - |
| LOW | postinstall file download | 9 | dist/transport/http.jsREADME.mddist/sampling.js +6 more | - |
| LOW | NoUseWeakRandom | 1 | dist/session-manager.js | - |
| LOW | postinstall persistence mechanism | 6 | dist/server.d.tsdist/index.d.tsdist/types.d.ts +3 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
11 rules(103 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
@claude-flow/mcp is a standalone Model Context Protocol server, version 3.0.0, published by ruvnet, the maintainer behind claude-flow. It speaks stdio, HTTP and WebSocket, pools connections and keeps a tool registry. It declares no browser permissions and no host permissions, which matches what it is: a server process that runs in a terminal or an agent host.
The scanner matched no tool-poisoning patterns anywhere in the package. That is the finding that matters most here, because an MCP framework that registers tools is exactly where hidden model-facing directives would sit. There are none, in dist/ or elsewhere. The registry code defines tools for a host to call; it does not hide instructions inside tool metadata.
The three network hits are the only code-level findings worth reading. NET-FETCH-dist/oauth.js-99 and NET-FETCH-dist/oauth.js-134 sit in dist/oauth.js, the OAuth client used when a client authorizes against a remote endpoint. Fetching a token URL is that file's job. NET-FETCH-dist/sampling.js-231 sits in dist/sampling.js, the implementation of MCP sampling, where a server asks the connected client or a configured model endpoint for a completion. That request is the feature. The declared endpoints line up with this: api.anthropic.com for model traffic, modelcontextprotocol.io and spec.modelcontextprotocol.io for the protocol spec, opensource.org and img.shields.io for license and badge links. Nothing here points somewhere the package does not claim to go.
Credential scope is thin. No finding matches a read of .ssh, .aws/credentials, .kube/config or application_default_credentials.json, and the credential-access category is empty. The only credential handling is the OAuth client credentials dist/oauth.js needs to reach the authorization server it is configured with, which is setup rather than theft.
The remaining findings are noise. 103 are low-severity code-smell rules of the kind that fire on any compiled JavaScript, and 30 are IoC extractions from dist/ output. dist/oauth.js and dist/sampling.js are build artifacts, so a single minified line can generate several indicators that mean nothing by themselves. Counting them suggests a problem; reading them shows there is none.
The strongest counterargument is that 136 findings is a large number, and a server with stdio, HTTP and WebSocket transports plus a tool registry can reach the filesystem, the network and a model endpoint. That breadth is real, and it is also what the package advertises. Capability in a framework is not evidence of abuse. Nothing in this evidence shows a read of a sensitive path, a call to an unexplained domain, or a hidden instruction, and those three things are what would change the verdict.
One limit on this review: the evidence covers built output only, with no source tree and no version history. A future release that adds credential-file reads next to a new outbound domain would deserve a fresh look.
Key Reasons
- Zero tool-poisoning findings in an MCP server that registers tools; no hidden model-facing directives in tool metadata
- The only network findings are NET-FETCH hits in dist/oauth.js and dist/sampling.js, which implement OAuth token exchange and MCP sampling, both of which require an HTTP call
- Declared endpoints (api.anthropic.com, modelcontextprotocol.io, spec.modelcontextprotocol.io, opensource.org, img.shields.io) all match the package's stated purpose
- No credential-file access: no .ssh, .aws/credentials, .kube/config or application_default_credentials.json reads, and no secret findings
- 103 of 136 findings are low-severity code-smell rules on compiled dist/ JavaScript and 30 are IoC extractions from minified build output
False Positive Considerations
- Low-severity code-smell rules firing on compiled dist/ JavaScript
- IoC extraction from minified dist/ bundle lines
- Legitimate OAuth and sampling HTTP calls flagged as NET-FETCH
- No permissions declared, so there is no over-permission finding to weigh
Reviewed 2026-09-30; recommended action: no action; model confidence 80%.
MCP version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace