MCP Registry

@kya-os/mcp-i-cloudflare

by h0bb5
57897dc8-a33c-56ab-9a92-43d2c33b09c6 | v1.15.1
82/ 100
HIGH risk
No change since v1.15.0
Analyst verdict
Benign but powerful

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
2 days ago
Version
v1.15.1
Artifact
SHA256 2C2…8EA
Source
Findings (non-IoC)

Is @kya-os/mcp-i-cloudflare safe?

@kya-os/mcp-i-cloudflare is a Cloudflare Workers adapter for the MCP-I framework, written by developer h0bb5. It runs MCP tool calls on Cloudflare's edge, including the OAuth-style handoff where one service asks another for permission before acting. The package declares no special permissions, and the manifest lists no network endpoints, which fits a library that only calls whatever provider you wire it up to.

The scan flagged 83 medium network findings, all of them fetch calls inside the package's own compiled code, in files like dist/delegation-http/native-oauth.js, dist/delegation-http/consent-anchor-bridge.js and dist/audit/durable-producer.js. Those are pattern matches on a fetch call, and a file named native-oauth is expected to make network requests. If one of them hit a host unrelated to a consent flow it would matter, but no external domains show up anywhere in the scan, and there are no reads of private key material such as .ssh or .aws/credentials. Three matches for MCP-TRANSPORT-HARDCODED-TOKEN in dist/services/consent.service.js and dist/constants.d.ts are the one thing I would look at twice. A token baked into shipped code can be a leak, though a token-shaped constant in a consent service is more often a placeholder.

The scanner tripped on the volume of network calls in a package whose main job is making network calls, and on token-shaped strings in the files that handle consent. Neither is the package misbehaving. That assessment rests on what is missing as much as what is present: no hidden instructions aimed at an AI agent, no sensitive credential reads paired with an unknown destination, and no malware or obfuscation signatures.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

86 detail rows
Showing 25 of 86 · highest severity first

Finding Categories

3
Secrets
83
Network

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

@kya-os/mcp-i-cloudflare is the Cloudflare Workers adapter for the MCP-I framework, published by h0bb5. The scan returned 86 findings across two categories, and the shape of those findings matters more than their number.

There are no tool-poisoning hits at all. For an MCP package that is the first thing I check, and the tool-poisoning rules matched nothing. MCP-I is a framework for defining tools, so description strings exist in the source, but nothing here carries directives aimed at an AI agent. Nothing tells the model to hide its actions, ignore instructions, or reroute data through another tool.

The bulk of the volume is 83 medium NET-FETCH matches. They sit in the framework's own compiled code, not in bundled third-party packages: dist/delegation-http/pickup-routes.js, dist/delegation-http/native-oauth.js, dist/delegation-http/native-oauth-state.js, dist/delegation-http/consent-anchor-bridge.js, dist/delegation-http/credential-consent.js, and dist/audit/durable-producer.js. The filenames describe an OAuth delegation and consent flow. A Cloudflare Workers adapter for an MCP framework exists to make outbound HTTP calls, so fetch() turns up in nearly every module that talks to an identity provider or a consent endpoint. The scanner flags the fetch call itself, so the count reflects how much networking the framework does.

That last point decides the verdict. The bundle lists no IoC matches and no network endpoints. There is no external host to weigh against the project's stated purpose, and nothing pairs a read of a sensitive path such as .ssh or .aws/credentials with a call to an unknown domain. Credential harvest plus exfil to an unexpected host is the signature I look for, and neither half is present apart from three MCP-TRANSPORT-HARDCODED-TOKEN matches in dist/services/consent.service.js and dist/constants.d.ts. A token baked into a shipped package deserves a glance, but a token-shaped constant in a consent service and a constants file reads as a default or placeholder, not a live secret lifted out of the environment.

The strongest argument against treating this as benign is that same set of hardcoded-token findings. Three critical-severity secret matches are not nothing. But the rule matches token-like strings, and it fires in the two files whose entire job is consent and credential handling, which gives a plain explanation. It does not change what the code does, which is run an OAuth-style delegation flow on Cloudflare Workers.

Nothing in the scan shows data leaving for a host outside the framework's own flow. No malware signatures, no obfuscation, no dependency-confusion or typosquatting signal, and no version history that jumps out. This is a networking-heavy framework doing the networking it advertises.

Key Reasons

  • Zero tool-poisoning findings; the package defines MCP tools rather than carrying hidden AI directives.
  • All 83 network findings are fetch calls in the package's own dist/ OAuth, delegation and consent code, which is the adapter's core function.
  • No credential-access findings against .ssh, .aws or .kube paths and no listed network endpoints, so there is no harvest-plus-exfil pairing.
  • Three MCP-TRANSPORT-HARDCODED-TOKEN matches in dist/services/consent.service.js and dist/constants.d.ts are pattern matches on token-shaped constants that handle consent.
  • No malware, IoC, obfuscation or code-smell findings to support a malicious reading.

False Positive Considerations

  • NET-FETCH rules match every fetch() call in an HTTP-heavy Cloudflare Workers adapter, inflating counts without indicating destination.
  • network_endpoints and IoC lists are empty, so no suspicious domain exists to corroborate the network findings.
  • Hardcoded-token rules match token-shaped constants in consent and constants files, which are commonly placeholders.
  • 84 of 86 findings are medium-severity network pattern matches, a volume-driven signal rather than a behavior-driven one.

Reviewed 2026-09-30; recommended action: monitor; model confidence 70%.

MCP version history

Risk trend by version

21 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
82
Change since first
-4
Change from previous
No change
Versions:
First analyzed version
1.9.1
May 1, 2026
Risk range
82 to 88
Across analyzed versions
Latest analyzed version
1.15.1
Sep 29, 2026
Selected version
high
Version
v1.15.1
2 days ago
Risk score
82
Findings
86
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Cloudflare Workers adapter for MCP-I framework

Frequently Asked Questions