MCP Registry

aismemory

653fe947-91d5-5c0b-84df-126399317cbf | v0.8.2
100/ 100
CRITICAL risk
No change since v0.8.0
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v0.8.2
Artifact
SHA256 513…7BF
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

486 detail rows
Showing 25 of 35 · highest severity first

YARA Rule Matches

12 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 57
dist/__tests__/agent-key-mode-e2e.test.jsdist/__tests__/provisional-token-reauth.test.jsdist/__tests__/mcp-tools.test.js +54 more
-
LOWpostinstall persistence mechanism 19
dist/__tests__/credential-resolution.test.jsdist/version-check.jsdist/__tests__/agent-key-mode-e2e.test.js +16 more
-
LOWpostinstall file download 61
dist/cli/enable-key-auth.jsdist/__tests__/mcp-tools.test.jsdist/ais-http.js +58 more
-
LOWNoUseWeakRandom 3
dist/__tests__/key-auth.test.jsdist/token-manager.jsdist/__tests__/silent-renewal-e2e.test.js
-
LOWpostinstall obfuscation 30
dist/__tests__/token-expiry-reauth.test.jsdist/__tests__/workspace-key-mode.test.jsdist/__tests__/reconnect-survival-e2e.test.js +27 more
-
LOWpostinstall system command 51
dist/__tests__/install.test.jsdist/__tests__/agent-load-persistence.test.jsdist/__tests__/credential-resolution.test.js +48 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 25
dist/__tests__/pending-device-flow-e2e.test.jsdist/__tests__/token-rejection-reauth-e2e.test.jsdist/__tests__/memory-write-failure.test.js +22 more
-
LOWpostinstall crypto operations 30
dist/session-identity.jsdist/pipeline/dedupe.jsdist/pipeline/ingestion.d.ts +27 more
-
LOWpostinstall network communication 50
dist/mcp/tools.jsdist/env-agent.d.tsdist/agent-preference.d.ts +47 more
-
LOWpostinstall file manipulation 62
dist/local-mirror.jsdist/__tests__/agent-archive.test.jsdist/__tests__/silent-renewal-e2e.test.js +59 more
-
LOWpostinstall registry modification 7
README.mddist/cli/doctor.d.tsdist/version-check.js +4 more
-
LOWpostinstall environment access 56
dist/__tests__/pipeline-scope-resolver.test.jsdist/__tests__/pending-device-flow-resume.test.jsdist/__tests__/agent-preference.test.js +53 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

142 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

11
Secrets
13
Network
142
IoC Indicators

YARA Rules Matched

12 rules(451 hits)
credential env files postinstall persistence mechanism postinstall file download NoUseWeakRandom postinstall obfuscation postinstall system command UsingShellInterpreterWhenExecutingOSCommands postinstall crypto operations postinstall network communication postinstall file manipulation postinstall registry modification postinstall environment access

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The aismemory package is an MCP server that provides persistent memory for AI agents by connecting to an Agent Identity Service. The scanner flagged 628 findings, but a detailed review shows these are almost entirely false positives from bundled dependencies and test fixtures.

Tool poisoning is the defining threat for MCP servers, and this package has zero tool-poisoning findings. No hidden instructions, no Unicode steganography, no XML-style directive tags in tool descriptions. The package defines tools for memory operations without embedding manipulative directives aimed at the AI agent.

The 11 critical-severity secret findings all carry the title MCP-TRANSPORT-HARDCODED-TOKEN and every single one is in a dist/tests/ file. These are test fixtures for pending-device-flow-e2e.test.js, install.test.js, agent-key-mode.test.js, and similar test files. Hardcoded tokens in test code are expected. Test suites need fixture data to validate authentication flows. This is not credential theft. It's a test harness.

The 13 network findings (NET-FETCH) appear in dist/refresh.js, dist/ais-http.js, dist/pipeline/bulk-store.js, and other bundled files. The network endpoints extracted from the package include agentsandswarms.ai, ais.agentsandswarms.ai, and www.agentsandswarms.ai. These align with the package's stated purpose of connecting to an Agent Identity Service. The endpoint claude.ai is a legitimate AI service. The domains evil.example, other.example, and ais.example are clearly test placeholders. No network calls go to unexpected or suspicious domains.

The 455 code-smell findings are all low severity and concentrated in dist/ files. These are bundled dependencies. The scanner's YARA rules fire on minified JavaScript from webpack or esbuild output. A single bundled file can trigger dozens of matches from the libraries it contains. This is a known false positive pattern. The 142 IoC findings follow the same pattern. IoC extraction from bundled code produces noise. Property access chains, IPv6 fragments, and CDN domains inflate the count without indicating real risk.

The strongest counterargument is that the developer name "GitHub Actions" is unusual for an npm publisher, and the user count is zero. A new package with no users and a misleading publisher name could be a supply chain attack. However, the code itself shows no malicious behavior. The network calls match the documented API. The test fixtures are expected. There is no credential harvesting, no exfiltration architecture, no tool poisoning. The package does what it says it does.

The combination of zero tool poisoning, test-only secret findings, expected network endpoints, and bundled-dependency noise means this package is safe to use despite the high finding count.

Key Reasons

  • Zero tool-poisoning findings across the entire package
  • All 11 critical secret findings are in test files (dist/tests/) where hardcoded tokens are expected
  • Network calls go to documented API endpoints (agentsandswarms.ai) matching the package's stated purpose
  • 455 code-smell findings are in bundled dist/ files, a known false positive pattern
  • No credential harvesting or exfiltration architecture detected

False Positive Considerations

  • Bundled dependencies in dist/ files triggering 455 code-smell findings
  • Test fixtures with hardcoded tokens in dist/tests/ files
  • IoC extraction from bundled code producing 142 noise findings
  • Test and example domains (evil.example, other.example) in network endpoints

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 82%.

MCP version history

Risk trend by version

9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
100
Change since first
+50
Change from previous
No change
Versions:
First analyzed version
0.5.2
Jun 22, 2026
Risk range
50 to 100
Across analyzed versions
Latest analyzed version
0.8.2
Sep 29, 2026
Selected version
critical
Version
v0.8.2
2 days ago
Risk score
100
Findings
628
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Persistent memory for AI agents. MCP server that connects to Agent Identity Service.

Frequently Asked Questions