From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- Today
- Version
- v3.50.0
- Artifact
- SHA256 573…654
- Source
- Findings (non-IoC)
Is @claude-flow/cli safe?
Claude Flow CLI is a command line tool from the publisher ruvnet that orchestrates AI coding agents, and it also runs an MCP server so agents can call its tools. It declares no browser permissions. Its code talks to endpoints including agents-goal.ruv.io and beta-flo.ruv.io, both on the maintainer's own ruv.io domain, along with commonly seen hosts like anthropic.com and amazon.com. The network hits sit inside modules whose whole job is making network calls, such as dist/src/mcp-tools/http-fetch-tools.js.
Two critical items stand out: MCP-TRANSPORT-HARDCODED-TOKEN, found in dist/src/mcp-tools/browser-intent-tools.js and its type declaration file. That means a default token is written into the source instead of being generated per install. If it unlocked a shared remote service, anyone reading the published code could use it. In this case it belongs to the browser bridge module, and nothing in the findings shows it sending anything off the machine. The other hits are ordinary fetch calls inside the tool that exists to fetch URLs.
The scanner also logged thousands of code-smell matches and over a thousand compromise indicators. Those come from the bundled dist/ folder, which packs compiled copies of many libraries into single files. That explains why the counts are so large and why the endpoint list includes entries like 0001-browser-skills-architecture.md, which is a markdown filename, and agent.total, which is a property lookup. No tool-poisoning patterns were detected in any tool description, and no code reads SSH keys, AWS credentials, or Kubernetes configs.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
14 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall file download | 173 | dist/src/plugins/tests/standalone-test.jsdist/src/transfer/store/search.jsdist/src/mcp-tools/managed-agent-tools.d.ts +170 more | - |
| LOW | credential gcp credentials | 1 | dist/src/transfer/storage/gcs.js | - |
| LOW | SQLInjection | 3 | dist/src/memory/memory-bridge.js.claude/skills/v3-cli-modernization/SKILL.mddist/src/mcp-tools/workflow-tools.js | - |
| LOW | NoUseEval | 3 | dist/src/commands/analyze.jsdist/src/commands/security.jsdist/src/benchmarks/pretrain/index.js | - |
| LOW | NoUseWeakRandom | 46 | .claude/agents/v3/collective-intelligence-coordinator.mddist/src/services/headless-worker-executor.jsdist/src/mcp-tools/coordination-tools.js +43 more | - |
| LOW | credential env files | 161 | dist/src/funnel/precedence.jsdist/src/transfer/ipfs/upload.jsplugins/ruflo-metaharness/scripts/audit-trend.mjs +158 more | - |
| LOW | postinstall persistence mechanism | 84 | plugins/ruflo-metaharness/agents/metaharness-architect.md.claude/agents/github/workflow-automation.mddist/src/services/swarm-memory-branches.js +81 more | - |
| LOW | ServerCertificatesNotVerified | 6 | dist/src/commands/ruvector/benchmark.jsdist/src/commands/ruvector/optimize.jsdist/src/commands/ruvector/backup.js +3 more | - |
| LOW | postinstall crypto operations | 1 | bin/mcp-server.js | - |
| LOW | postinstall obfuscation | 240 | .claude/agents/swarm/adaptive-coordinator.mddist/src/log-filters.d.tsdist/src/memory/scm-classifier.js +237 more | - |
| LOW | postinstall registry modification | 136 | dist/src/services/worker-daemon.d.tsdist/src/commands/migrate.jsplugins/ruflo-metaharness/scripts/_harness.mjs +133 more | - |
| LOW | AlertStatementsShouldNotBeUsed | 1 | dist/src/prompt.d.ts | - |
| LOW | postinstall environment access | 32 | dist/src/services/policy-runtime.d.tsdist/src/commands/hooks.jsdist/src/services/harness-flywheel-runtime.d.ts +29 more | - |
| LOW | postinstall file manipulation | 45 | dist/src/commands/funnel.jsdist/src/memory/memory-bridge.d.tsdist/src/ruvector/task-embedder.js +42 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
14 rules(932 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Claude Flow CLI (@claude-flow/cli, version 3.48.0) from publisher ruvnet is a large JavaScript orchestrator that registers dozens of MCP tools. The findings separate cleanly into deliberate feature code and bulk noise, and none of them describe an attack.
Tool poisoning. The scan matched zero tool-poisoning patterns. That is the important result here, because this package ships a pile of tool definitions under dist/src/mcp-tools/, which is exactly the shape of code that normally produces description-field false positives. There are no directives aimed at an AI agent, no instruction tags, and no invisible Unicode hidden in tool names or descriptions. Nothing in the metadata tries to steer model behavior.
Credentials and network. The only critical-severity items are MCP-TRANSPORT-HARDCODED-TOKEN in dist/src/mcp-tools/browser-intent-tools.js and its .d.ts companion. That is a baked-in default token for the transport layer, and no harvested secret shows up alongside it. No finding touches .ssh/, .aws/credentials, .kube/config, or application_default_credentials.json. The network calls land where the feature set says they should: dist/src/mcp-tools/http-fetch-tools.js:290 and :205 sit inside the module whose stated job is fetching URLs; x-federation-join.js:39 and x-federation-channels.js:52 open websocket channels for the federation feature; plugins/store/discovery.js:15 and :21 perform plugin store lookups; agent-execute-core.js:166 and :329 drive agent execution. The named hosts agents-goal.ruv.io and beta-flo.ruv.io are on the maintainer's own ruv.io domain, which is the service this CLI is built to talk to. The remainder of the endpoint list is extractor output, not infrastructure: markdown filenames such as 0001-browser-skills-architecture.md and adr-150-metaharness-integration-surfaces.md, and property chains such as agent.total, brain.domains, cached.report and categories.management that are not hosts at all.
Volume. Thousands of code-smell hits and over a thousand indicators come from bundled dist/ output, where compiled copies of many libraries sit in single files. Malware-signature matches are zero and obfuscation findings are zero, so the large numbers reflect bundle size rather than hidden payloads.
Strongest counterargument. The hardcoded token is the best case against this reading. If that token were shared across every install and unlocked a remote service, anyone who reads the published tarball could use it. It lives in browser-intent-tools.js, a module that talks to a browser bridge, and default tokens for local-only transports are a common shortcut. Nothing in the findings shows the token being transmitted anywhere. The second counterargument is breadth: 66 network findings plus websocket federation means this package can reach out a great deal, and a broad agent orchestrator is a large trust surface. Breadth is not intent, and every destination that resolves to a real host belongs to the project or a well-known service.
The code does what its description says it does, at scale.
Key Reasons
- Zero tool-poisoning findings across a package that ships dozens of MCP tool definitions under dist/src/mcp-tools/
- No credential-access findings against .ssh, .aws/credentials, .kube/config, or application_default_credentials.json
- Network calls cluster in deliberate feature modules (http-fetch-tools.js, x-federation-join.js, plugins/store/discovery.js) and in the maintainer's own ruv.io endpoints
- The only critical results are MCP-TRANSPORT-HARDCODED-TOKEN defaults in browser-intent-tools.js, not stolen secrets
- Zero malware-signature and zero obfuscation findings; the remaining volume is bundled dist/ code and IoC extractor noise
False Positive Considerations
- 2402 YARA code-smell matches firing on bundled dist/ JavaScript
- 1049 IoC hits including markdown filenames and property chains misread as domains
- NET-FETCH hits that correspond to the package's own HTTP fetch tool implementations
- No manifest or dependency findings, so scoring is driven almost entirely by code-smell and IoC volume
Reviewed 2026-09-30; recommended action: no action; model confidence 76%.
MCP version history
Risk trend by version
118 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace