MCP Registry

mcp-proxy

61d7b3d8-b259-5a1a-9c45-1510e64ea520 | v6.7.19
100/ 100
CRITICAL risk
No change since v6.7.18
Analyst verdict
Benign but powerful

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
1 weeks ago
Version
v6.7.19
Artifact
SHA256 DDD…665
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

240 detail rows
Showing 25 of 103 · highest severity first

YARA Rule Matches

14 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 15
dist/startStdioServer-DHm0KcPu.mjs.mapsrc/startHTTPServer.modern-era-guard.test.tssrc/startHTTPServer.ts +12 more
-
LOWHavingAPermissiveCrossOriginResourceSharingPolicy 2
dist/startStdioServer-DHm0KcPu.mjssrc/startHTTPServer.ts
-
LOWNoUseWeakRandom 3
src/InMemoryEventStore.tsdist/startStdioServer-DHm0KcPu.mjsdist/startStdioServer-DHm0KcPu.mjs.map
-
LOWpostinstall network communication 32
src/fixtures/backwards-compatible-http-server.tssrc/InMemoryEventStore.tsdist/index.mjs +29 more
-
LOWpostinstall system command 12
src/StdioClientTransport.test.tsREADME.mdsrc/protocolEras.test.ts +9 more
-
LOWpostinstall file manipulation 19
src/authentication.test.tssrc/upstreamNotifications.test.tssrc/upstreamNotifications.ts +16 more
-
LOWpostinstall environment access 13
src/startHTTPServer.headers-sent.test.tssrc/startStdioServer.tssrc/startHTTPServer.get-stream-error.test.ts +10 more
-
LOWpostinstall registry modification 2
dist/startStdioServer-DHm0KcPu.mjsdist/startStdioServer-DHm0KcPu.mjs.map
-
LOWpostinstall obfuscation 9
README.mdsrc/startHTTPServer.test.tsdist/bin/mcp-proxy.mjs.map +6 more
-
LOWpostinstall crypto operations 6
dist/bin/mcp-proxy.mjs.mapsrc/fixtures/backwards-compatible-http-server.tssrc/authentication.ts +3 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 2
dist/bin/mcp-proxy.mjs.mapsrc/startStdioServer.test.ts
-
LOWUsingCommandLineArguments 2
dist/bin/mcp-proxy.mjs.mapdist/bin/mcp-proxy.mjs
-
LOWcredential env files 14
dist/bin/mcp-proxy.mjs.mapsrc/StdioClientTransport.test.tssrc/fixtures/backwards-compatible-http-server.ts +11 more
-
LOWpostinstall persistence mechanism 6
src/fixtures/noisy-stdout-server.tssrc/upstreamNotifications.tsdist/startStdioServer-DHm0KcPu.mjs +3 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

63 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

12
Secrets
77
Network
63
IoC Indicators

YARA Rules Matched

14 rules(137 hits)
postinstall file download HavingAPermissiveCrossOriginResourceSharingPolicy NoUseWeakRandom postinstall network communication postinstall system command postinstall file manipulation postinstall environment access postinstall registry modification postinstall obfuscation postinstall crypto operations UsingShellInterpreterWhenExecutingOSCommands UsingCommandLineArguments credential env files postinstall persistence mechanism

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Tool Poisoning Assessment: The findings summary shows 0 tool-poisoning findings. This is the critical metric for MCP server security. Tool poisoning is the defining threat for MCP packages, involving hidden AI manipulation directives embedded in tool descriptions. With zero findings in this category, there is no evidence of hidden instructions aimed at manipulating AI agent behavior.

Credential and Network Access: The findings summary shows 21 secret findings and 27 network findings, but the evidence bundle does not contain specific credential-access findings targeting sensitive paths like .ssh/, .aws/credentials, .kube/config, or application_default_credentials.json. The IoC findings are exclusively documentation and issue tracker URLs: https://developer.mozilla.org/docs/Web/API/EventSource/, https://github.com/sindresorhus/get-east-asian-width/pull/6, https://openid.net/specs/openid-connect-discovery-1_0.html, and http://stackoverflow.com/questions/13227489. The only non-documentation domain is https://tunnel.gla.ma, but without code evidence showing this domain is used for data exfiltration combined with credential harvesting, this is likely a dependency reference. The combination of credential reads + network calls to unknown domains is the exfiltration signal—neither alone is sufficient, and neither is present here.

False Positive Drivers: The 760 total findings are inflated by bundled dependencies. The IoC count of 555 consists of documentation URLs from standard npm packages. The 95 malware-signature findings are typical for bundled node_modules in dist/ files. The package description states it is "A TypeScript SSE proxy for MCP servers that use stdio transport"—legitimate infrastructure code that orchestrates MCP tool definitions rather than poisoning them.

Strongest Counterargument: The developer name "GitHub Actions" is unusual and could indicate automated or anonymous publishing. However, this alone does not constitute malicious behavior. The package serves a legitimate infrastructure purpose (SSE proxy for stdio transport), has zero tool-poisoning findings, and the IoC findings are all benign documentation references. The high finding count is expected for any MCP package with bundled dependencies and does not indicate malicious intent.

Conclusion: This is a legitimate MCP infrastructure package. The high finding counts are false positives from bundled code and documentation URLs. No evidence of tool poisoning, credential theft, or data exfiltration architecture.

Key Reasons

  • Zero tool-poisoning findings in a package with 760 total findings
  • All IoC findings are documentation/issue tracker URLs, not exfiltration endpoints
  • No credential-access findings targeting sensitive paths (.ssh, .aws, .kube)
  • Package description indicates legitimate infrastructure purpose (SSE proxy for stdio transport)

False Positive Considerations

  • Bundled dependencies generating high IoC and malware-signature counts
  • Documentation URLs from npm package metadata
  • Code-smell findings from standard Node.js patterns
  • Minified/bundled JavaScript triggering YARA rules

Reviewed 2026-04-27; recommended action: no action; model confidence 85%.

MCP version history

Risk trend by version

22 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
100
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
6.5.0
May 12, 2026
Risk range
100 to 100
Across analyzed versions
Latest analyzed version
6.7.19
Sep 21, 2026
Selected version
critical
Version
v6.7.19
1 weeks ago
Risk score
100
Findings
303
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

A TypeScript SSE proxy for MCP servers that use stdio transport.

Frequently Asked Questions