MCP Registry

@claude-flow/cli

by ruvnet
4df61601-e2c0-5edc-9c4f-5f046e1b0110 | v3.50.0
82/ 100
HIGH risk
No change since v3.49.0
Analyst verdict
Benign but powerful

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
Today
Version
v3.50.0
Artifact
SHA256 573…654
Source
Findings (non-IoC)

Is @claude-flow/cli safe?

Claude Flow CLI is a command line tool from the publisher ruvnet that orchestrates AI coding agents, and it also runs an MCP server so agents can call its tools. It declares no browser permissions. Its code talks to endpoints including agents-goal.ruv.io and beta-flo.ruv.io, both on the maintainer's own ruv.io domain, along with commonly seen hosts like anthropic.com and amazon.com. The network hits sit inside modules whose whole job is making network calls, such as dist/src/mcp-tools/http-fetch-tools.js.

Two critical items stand out: MCP-TRANSPORT-HARDCODED-TOKEN, found in dist/src/mcp-tools/browser-intent-tools.js and its type declaration file. That means a default token is written into the source instead of being generated per install. If it unlocked a shared remote service, anyone reading the published code could use it. In this case it belongs to the browser bridge module, and nothing in the findings shows it sending anything off the machine. The other hits are ordinary fetch calls inside the tool that exists to fetch URLs.

The scanner also logged thousands of code-smell matches and over a thousand compromise indicators. Those come from the bundled dist/ folder, which packs compiled copies of many libraries into single files. That explains why the counts are so large and why the endpoint list includes entries like 0001-browser-skills-architecture.md, which is a markdown filename, and agent.total, which is a property lookup. No tool-poisoning patterns were detected in any tool description, and no code reads SSH keys, AWS credentials, or Kubernetes configs.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 69 · highest severity first

YARA Rule Matches

15 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 173
dist/src/mcp-tools/managed-agent-tools.d.tsdist/src/mcp-tools/agentbbs-tools.js.claude/skills/skill-builder/SKILL.md +170 more
-
LOWcredential gcp credentials 1
dist/src/transfer/storage/gcs.js
-
LOWSQLInjection 3
.claude/skills/v3-cli-modernization/SKILL.mddist/src/mcp-tools/workflow-tools.jsdist/src/memory/memory-bridge.js
-
LOWNoUseEval 3
dist/src/commands/analyze.jsdist/src/commands/security.jsdist/src/benchmarks/pretrain/index.js
-
LOWNoUseWeakRandom 46
.claude/agents/swarm/adaptive-coordinator.mddist/src/mcp-tools/terminal-tools.jsdist/src/fs-secure.js +43 more
-
LOWcredential env files 161
dist/src/init/claudemd-generator.jsdist/src/mods/probe.jsdist/src/funnel/precedence.js +158 more
-
LOWpostinstall persistence mechanism 84
dist/src/services/swarm-memory-branches.js.claude/agents/flow-nexus/payments.mddist/src/config/proven-config-refresh.d.ts +81 more
-
LOWServerCertificatesNotVerified 6
dist/src/commands/ruvector/benchmark.jsdist/src/commands/ruvector/optimize.jsdist/src/commands/ruvector/backup.js +3 more
-
LOWDebuggerStatementsShouldNotBeUsed 20
.claude/commands/pair/start.md.claude/agents/github/swarm-issue.mddist/src/ruvector/q-learning-router.js +17 more
-
LOWUsingCommandLineArguments 37
dist/src/init/helpers-generator.js.claude/helpers/statusline.cjsdist/src/benchmarks/gaia-decomposer.smoke.js +34 more
-
LOWpostinstall crypto operations 1
dist/src/appliance/rvfa-runner.d.ts
-
LOWpostinstall obfuscation 240
.claude/agents/optimization/performance-monitor.mddist/src/commands/doctor.jsdist/src/benchmarks/gaia-tools/file_read.js +237 more
-
LOWpostinstall registry modification 136
dist/src/commands/security.jsdist/src/commands/daemon.jsdist/src/mcp-tools/agentbbs-federation.d.ts +133 more
-
LOWAlertStatementsShouldNotBeUsed 1
dist/src/prompt.d.ts
-
LOWpostinstall environment access 19
dist/src/services/memory-backup.d.tsdist/src/memory/sibling-store.d.tsdist/src/services/distill-tuning.d.ts +16 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

1,043 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

2
Secrets
66
Network
1,043
IoC Indicators

YARA Rules Matched

15 rules(931 hits)
postinstall file download credential gcp credentials SQLInjection NoUseEval NoUseWeakRandom credential env files postinstall persistence mechanism ServerCertificatesNotVerified DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments postinstall crypto operations postinstall obfuscation postinstall registry modification AlertStatementsShouldNotBeUsed postinstall environment access

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Claude Flow CLI (@claude-flow/cli, version 3.48.0) from publisher ruvnet is a large JavaScript orchestrator that registers dozens of MCP tools. The findings separate cleanly into deliberate feature code and bulk noise, and none of them describe an attack.

Tool poisoning. The scan matched zero tool-poisoning patterns. That is the important result here, because this package ships a pile of tool definitions under dist/src/mcp-tools/, which is exactly the shape of code that normally produces description-field false positives. There are no directives aimed at an AI agent, no instruction tags, and no invisible Unicode hidden in tool names or descriptions. Nothing in the metadata tries to steer model behavior.

Credentials and network. The only critical-severity items are MCP-TRANSPORT-HARDCODED-TOKEN in dist/src/mcp-tools/browser-intent-tools.js and its .d.ts companion. That is a baked-in default token for the transport layer, and no harvested secret shows up alongside it. No finding touches .ssh/, .aws/credentials, .kube/config, or application_default_credentials.json. The network calls land where the feature set says they should: dist/src/mcp-tools/http-fetch-tools.js:290 and :205 sit inside the module whose stated job is fetching URLs; x-federation-join.js:39 and x-federation-channels.js:52 open websocket channels for the federation feature; plugins/store/discovery.js:15 and :21 perform plugin store lookups; agent-execute-core.js:166 and :329 drive agent execution. The named hosts agents-goal.ruv.io and beta-flo.ruv.io are on the maintainer's own ruv.io domain, which is the service this CLI is built to talk to. The remainder of the endpoint list is extractor output, not infrastructure: markdown filenames such as 0001-browser-skills-architecture.md and adr-150-metaharness-integration-surfaces.md, and property chains such as agent.total, brain.domains, cached.report and categories.management that are not hosts at all.

Volume. Thousands of code-smell hits and over a thousand indicators come from bundled dist/ output, where compiled copies of many libraries sit in single files. Malware-signature matches are zero and obfuscation findings are zero, so the large numbers reflect bundle size rather than hidden payloads.

Strongest counterargument. The hardcoded token is the best case against this reading. If that token were shared across every install and unlocked a remote service, anyone who reads the published tarball could use it. It lives in browser-intent-tools.js, a module that talks to a browser bridge, and default tokens for local-only transports are a common shortcut. Nothing in the findings shows the token being transmitted anywhere. The second counterargument is breadth: 66 network findings plus websocket federation means this package can reach out a great deal, and a broad agent orchestrator is a large trust surface. Breadth is not intent, and every destination that resolves to a real host belongs to the project or a well-known service.

The code does what its description says it does, at scale.

Key Reasons

  • Zero tool-poisoning findings across a package that ships dozens of MCP tool definitions under dist/src/mcp-tools/
  • No credential-access findings against .ssh, .aws/credentials, .kube/config, or application_default_credentials.json
  • Network calls cluster in deliberate feature modules (http-fetch-tools.js, x-federation-join.js, plugins/store/discovery.js) and in the maintainer's own ruv.io endpoints
  • The only critical results are MCP-TRANSPORT-HARDCODED-TOKEN defaults in browser-intent-tools.js, not stolen secrets
  • Zero malware-signature and zero obfuscation findings; the remaining volume is bundled dist/ code and IoC extractor noise

False Positive Considerations

  • 2402 YARA code-smell matches firing on bundled dist/ JavaScript
  • 1049 IoC hits including markdown filenames and property chains misread as domains
  • NET-FETCH hits that correspond to the package's own HTTP fetch tool implementations
  • No manifest or dependency findings, so scoring is driven almost entirely by code-smell and IoC volume

Reviewed 2026-09-30; recommended action: no action; model confidence 76%.

MCP version history

Risk trend by version

118 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
82
Change since first
+21
Change from previous
No change
Versions:
First analyzed version
3.5.82
Apr 27, 2026
Risk range
57 to 86
Across analyzed versions
Latest analyzed version
3.50.0
Oct 2, 2026
Selected version
high
Version
v3.50.0
Today
Risk score
82
Findings
3545
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Ruflo CLI - Enterprise AI agent orchestration with 60+ specialized agents, swarm coordination, MCP server, self-learning hooks, and vector memory for Claude Code

Frequently Asked Questions