mcp-proxy
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v6.7.19
- Artifact
- SHA256 DDD…665
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
14 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall file download | 15 | src/fixtures/backwards-compatible-http-server.tsREADME.md.github/workflows/feature.yaml +12 more | - |
| LOW | HavingAPermissiveCrossOriginResourceSharingPolicy | 2 | dist/startStdioServer-DHm0KcPu.mjssrc/startHTTPServer.ts | - |
| LOW | NoUseWeakRandom | 3 | dist/startStdioServer-DHm0KcPu.mjssrc/InMemoryEventStore.tsdist/startStdioServer-DHm0KcPu.mjs.map | - |
| LOW | credential env files | 14 | src/startStdioServer.test.tssrc/StdioClientTransport.test.tssrc/fixtures/backwards-compatible-http-server.ts +11 more | - |
| LOW | postinstall persistence mechanism | 6 | dist/startStdioServer-DHm0KcPu.mjs.mapsrc/fixtures/noisy-stdout-server.tssrc/upstreamNotifications.ts +3 more | - |
| LOW | UsingCommandLineArguments | 2 | dist/bin/mcp-proxy.mjsdist/bin/mcp-proxy.mjs.map | - |
| LOW | postinstall network communication | 32 | src/fixtures/backwards-compatible-http-server.tssrc/InMemoryEventStore.tsdist/index.mjs +29 more | - |
| LOW | postinstall system command | 12 | src/StdioClientTransport.test.tsREADME.mdsrc/protocolEras.test.ts +9 more | - |
| LOW | postinstall file manipulation | 19 | src/authentication.test.tssrc/upstreamNotifications.test.tssrc/upstreamNotifications.ts +16 more | - |
| LOW | postinstall environment access | 13 | src/startHTTPServer.headers-sent.test.tssrc/startStdioServer.tssrc/startHTTPServer.get-stream-error.test.ts +10 more | - |
| LOW | postinstall registry modification | 2 | dist/startStdioServer-DHm0KcPu.mjsdist/startStdioServer-DHm0KcPu.mjs.map | - |
| LOW | postinstall obfuscation | 9 | README.mdsrc/startHTTPServer.test.tsdist/bin/mcp-proxy.mjs.map +6 more | - |
| LOW | postinstall crypto operations | 6 | dist/bin/mcp-proxy.mjs.mapsrc/fixtures/backwards-compatible-http-server.tssrc/authentication.ts +3 more | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 2 | dist/bin/mcp-proxy.mjs.mapsrc/startStdioServer.test.ts | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
14 rules(137 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Tool Poisoning Assessment: The findings summary shows 0 tool-poisoning findings. This is the critical metric for MCP server security. Tool poisoning is the defining threat for MCP packages, involving hidden AI manipulation directives embedded in tool descriptions. With zero findings in this category, there is no evidence of hidden instructions aimed at manipulating AI agent behavior.
Credential and Network Access: The findings summary shows 21 secret findings and 27 network findings, but the evidence bundle does not contain specific credential-access findings targeting sensitive paths like .ssh/, .aws/credentials, .kube/config, or application_default_credentials.json. The IoC findings are exclusively documentation and issue tracker URLs: https://developer.mozilla.org/docs/Web/API/EventSource/, https://github.com/sindresorhus/get-east-asian-width/pull/6, https://openid.net/specs/openid-connect-discovery-1_0.html, and http://stackoverflow.com/questions/13227489. The only non-documentation domain is https://tunnel.gla.ma, but without code evidence showing this domain is used for data exfiltration combined with credential harvesting, this is likely a dependency reference. The combination of credential reads + network calls to unknown domains is the exfiltration signal—neither alone is sufficient, and neither is present here.
False Positive Drivers: The 760 total findings are inflated by bundled dependencies. The IoC count of 555 consists of documentation URLs from standard npm packages. The 95 malware-signature findings are typical for bundled node_modules in dist/ files. The package description states it is "A TypeScript SSE proxy for MCP servers that use stdio transport"—legitimate infrastructure code that orchestrates MCP tool definitions rather than poisoning them.
Strongest Counterargument: The developer name "GitHub Actions" is unusual and could indicate automated or anonymous publishing. However, this alone does not constitute malicious behavior. The package serves a legitimate infrastructure purpose (SSE proxy for stdio transport), has zero tool-poisoning findings, and the IoC findings are all benign documentation references. The high finding count is expected for any MCP package with bundled dependencies and does not indicate malicious intent.
Conclusion: This is a legitimate MCP infrastructure package. The high finding counts are false positives from bundled code and documentation URLs. No evidence of tool poisoning, credential theft, or data exfiltration architecture.
Key Reasons
- Zero tool-poisoning findings in a package with 760 total findings
- All IoC findings are documentation/issue tracker URLs, not exfiltration endpoints
- No credential-access findings targeting sensitive paths (.ssh, .aws, .kube)
- Package description indicates legitimate infrastructure purpose (SSE proxy for stdio transport)
False Positive Considerations
- Bundled dependencies generating high IoC and malware-signature counts
- Documentation URLs from npm package metadata
- Code-smell findings from standard Node.js patterns
- Minified/bundled JavaScript triggering YARA rules
Reviewed 2026-04-27; recommended action: no action; model confidence 85%.
MCP version history
Risk trend by version
22 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace