MCP Registry

@claude-flow/mcp

by ruvnet
4aaafb12-9f3c-50c7-9520-1c4eec14d448 | v3.0.0
54/ 100
MEDIUM risk
-2 since v3.0.0-alpha.10
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (54/100) still counts them.

Analysis record

Analysed
3 days ago
Version
v3.0.0
Artifact
SHA256 655…AEE
Source
Findings (non-IoC)

Is @claude-flow/mcp safe?

@claude-flow/mcp is a Model Context Protocol server that runs alongside an AI agent and gives it a standard way to reach tools, with stdio, HTTP and WebSocket transports, connection pooling and a tool registry. It declares no browser or host permissions. The addresses it talks to are api.anthropic.com for model traffic, modelcontextprotocol.io and spec.modelcontextprotocol.io for the protocol specification, and opensource.org and img.shields.io for license and badge links.

The findings worth naming come from three network calls: NET-FETCH-dist/oauth.js-99 and NET-FETCH-dist/oauth.js-134 in dist/oauth.js, and NET-FETCH-dist/sampling.js-231 in dist/sampling.js. Those files handle OAuth sign-in and MCP sampling, and both features are built around making an HTTP request, so a fetch there is the function doing its job. No finding reads .ssh, .aws or .kube files, and no address sits outside the package's own purpose.

The rest of the scan result is scanner noise. Most of it is low-severity code-smell rules that match any compiled JavaScript, plus a set of indicators pulled from the built files in dist/, where one minified line can be counted several times. That describes the shape of bundled output rather than behaviour.

If you are deciding whether to add this to an agent, the thing to know is that it is a framework with broad reach: it can pass tool calls, hold connections open and talk to a model endpoint. That reach is the point of it, and nothing in this scan shows it used for anything else.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

106 detail rows

YARA Rule Matches

11 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall crypto operations 2
dist/transport/http.jsdist/oauth.js
-
LOWpostinstall system command 11
dist/task-manager.d.tsdist/tool-registry.jsREADME.md +8 more
-
LOWpostinstall file manipulation 16
dist/connection-pool.jsdist/oauth.d.tsdist/task-manager.js +13 more
-
LOWDisablingContentSecurityPolicyFetchDirectives 1
dist/transport/http.js
-
LOWpostinstall registry modification 18
dist/resource-registry.js.mappackage.jsondist/server.js +15 more
-
LOWpostinstall network communication 27
dist/index.jsdist/connection-pool.jsdist/session-manager.js +24 more
-
LOWpostinstall obfuscation 11
dist/prompt-registry.d.tsdist/schema-validator.jsdist/schema-validator.d.ts +8 more
-
LOWNoUseEval 1
README.md
-
LOWpostinstall file download 9
dist/transport/http.jsREADME.mddist/sampling.js +6 more
-
LOWNoUseWeakRandom 1
dist/session-manager.js
-
LOWpostinstall persistence mechanism 6
dist/server.d.tsdist/index.d.tsdist/types.d.ts +3 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

30 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

3
Network
30
IoC Indicators

YARA Rules Matched

11 rules(103 hits)
postinstall crypto operations postinstall system command postinstall file manipulation DisablingContentSecurityPolicyFetchDirectives postinstall registry modification postinstall network communication postinstall obfuscation NoUseEval postinstall file download NoUseWeakRandom postinstall persistence mechanism

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

@claude-flow/mcp is a standalone Model Context Protocol server, version 3.0.0, published by ruvnet, the maintainer behind claude-flow. It speaks stdio, HTTP and WebSocket, pools connections and keeps a tool registry. It declares no browser permissions and no host permissions, which matches what it is: a server process that runs in a terminal or an agent host.

The scanner matched no tool-poisoning patterns anywhere in the package. That is the finding that matters most here, because an MCP framework that registers tools is exactly where hidden model-facing directives would sit. There are none, in dist/ or elsewhere. The registry code defines tools for a host to call; it does not hide instructions inside tool metadata.

The three network hits are the only code-level findings worth reading. NET-FETCH-dist/oauth.js-99 and NET-FETCH-dist/oauth.js-134 sit in dist/oauth.js, the OAuth client used when a client authorizes against a remote endpoint. Fetching a token URL is that file's job. NET-FETCH-dist/sampling.js-231 sits in dist/sampling.js, the implementation of MCP sampling, where a server asks the connected client or a configured model endpoint for a completion. That request is the feature. The declared endpoints line up with this: api.anthropic.com for model traffic, modelcontextprotocol.io and spec.modelcontextprotocol.io for the protocol spec, opensource.org and img.shields.io for license and badge links. Nothing here points somewhere the package does not claim to go.

Credential scope is thin. No finding matches a read of .ssh, .aws/credentials, .kube/config or application_default_credentials.json, and the credential-access category is empty. The only credential handling is the OAuth client credentials dist/oauth.js needs to reach the authorization server it is configured with, which is setup rather than theft.

The remaining findings are noise. 103 are low-severity code-smell rules of the kind that fire on any compiled JavaScript, and 30 are IoC extractions from dist/ output. dist/oauth.js and dist/sampling.js are build artifacts, so a single minified line can generate several indicators that mean nothing by themselves. Counting them suggests a problem; reading them shows there is none.

The strongest counterargument is that 136 findings is a large number, and a server with stdio, HTTP and WebSocket transports plus a tool registry can reach the filesystem, the network and a model endpoint. That breadth is real, and it is also what the package advertises. Capability in a framework is not evidence of abuse. Nothing in this evidence shows a read of a sensitive path, a call to an unexplained domain, or a hidden instruction, and those three things are what would change the verdict.

One limit on this review: the evidence covers built output only, with no source tree and no version history. A future release that adds credential-file reads next to a new outbound domain would deserve a fresh look.

Key Reasons

  • Zero tool-poisoning findings in an MCP server that registers tools; no hidden model-facing directives in tool metadata
  • The only network findings are NET-FETCH hits in dist/oauth.js and dist/sampling.js, which implement OAuth token exchange and MCP sampling, both of which require an HTTP call
  • Declared endpoints (api.anthropic.com, modelcontextprotocol.io, spec.modelcontextprotocol.io, opensource.org, img.shields.io) all match the package's stated purpose
  • No credential-file access: no .ssh, .aws/credentials, .kube/config or application_default_credentials.json reads, and no secret findings
  • 103 of 136 findings are low-severity code-smell rules on compiled dist/ JavaScript and 30 are IoC extractions from minified build output

False Positive Considerations

  • Low-severity code-smell rules firing on compiled dist/ JavaScript
  • IoC extraction from minified dist/ bundle lines
  • Legitimate OAuth and sampling HTTP calls flagged as NET-FETCH
  • No permissions declared, so there is no over-permission finding to weigh

Reviewed 2026-09-30; recommended action: no action; model confidence 80%.

MCP version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
54
Change since first
-1
Change from previous
-2
Versions:
First analyzed version
3.0.0-alpha.9
May 10, 2026
Risk range
54 to 56
Across analyzed versions
Latest analyzed version
3.0.0
Sep 28, 2026
Selected version
medium
Version
v3.0.0
3 days ago
Risk score
54
Findings
136
Change vs previous
-2

Pick any point on the chart to explore that version's code below.

About This Extension

Standalone MCP (Model Context Protocol) server - stdio/http/websocket transports, connection pooling, tool registry

Frequently Asked Questions