aismemory
The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v0.8.2
- Artifact
- SHA256 513…7BF
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
12 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 57 | dist/__tests__/agent-key-mode-e2e.test.jsdist/__tests__/provisional-token-reauth.test.jsdist/__tests__/mcp-tools.test.js +54 more | - |
| LOW | postinstall persistence mechanism | 19 | dist/__tests__/credential-resolution.test.jsdist/version-check.jsdist/__tests__/agent-key-mode-e2e.test.js +16 more | - |
| LOW | postinstall file download | 61 | dist/cli/enable-key-auth.jsdist/__tests__/mcp-tools.test.jsdist/ais-http.js +58 more | - |
| LOW | NoUseWeakRandom | 3 | dist/__tests__/key-auth.test.jsdist/token-manager.jsdist/__tests__/silent-renewal-e2e.test.js | - |
| LOW | postinstall obfuscation | 30 | dist/__tests__/token-expiry-reauth.test.jsdist/__tests__/workspace-key-mode.test.jsdist/__tests__/reconnect-survival-e2e.test.js +27 more | - |
| LOW | postinstall system command | 51 | dist/__tests__/install.test.jsdist/__tests__/agent-load-persistence.test.jsdist/__tests__/credential-resolution.test.js +48 more | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 25 | dist/__tests__/pending-device-flow-e2e.test.jsdist/__tests__/token-rejection-reauth-e2e.test.jsdist/__tests__/memory-write-failure.test.js +22 more | - |
| LOW | postinstall crypto operations | 30 | dist/session-identity.jsdist/pipeline/dedupe.jsdist/pipeline/ingestion.d.ts +27 more | - |
| LOW | postinstall network communication | 50 | dist/mcp/tools.jsdist/env-agent.d.tsdist/agent-preference.d.ts +47 more | - |
| LOW | postinstall file manipulation | 62 | dist/local-mirror.jsdist/__tests__/agent-archive.test.jsdist/__tests__/silent-renewal-e2e.test.js +59 more | - |
| LOW | postinstall registry modification | 7 | README.mddist/cli/doctor.d.tsdist/version-check.js +4 more | - |
| LOW | postinstall environment access | 56 | dist/__tests__/pipeline-scope-resolver.test.jsdist/__tests__/pending-device-flow-resume.test.jsdist/__tests__/agent-preference.test.js +53 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
12 rules(451 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The aismemory package is an MCP server that provides persistent memory for AI agents by connecting to an Agent Identity Service. The scanner flagged 628 findings, but a detailed review shows these are almost entirely false positives from bundled dependencies and test fixtures.
Tool poisoning is the defining threat for MCP servers, and this package has zero tool-poisoning findings. No hidden instructions, no Unicode steganography, no XML-style directive tags in tool descriptions. The package defines tools for memory operations without embedding manipulative directives aimed at the AI agent.
The 11 critical-severity secret findings all carry the title MCP-TRANSPORT-HARDCODED-TOKEN and every single one is in a dist/tests/ file. These are test fixtures for pending-device-flow-e2e.test.js, install.test.js, agent-key-mode.test.js, and similar test files. Hardcoded tokens in test code are expected. Test suites need fixture data to validate authentication flows. This is not credential theft. It's a test harness.
The 13 network findings (NET-FETCH) appear in dist/refresh.js, dist/ais-http.js, dist/pipeline/bulk-store.js, and other bundled files. The network endpoints extracted from the package include agentsandswarms.ai, ais.agentsandswarms.ai, and www.agentsandswarms.ai. These align with the package's stated purpose of connecting to an Agent Identity Service. The endpoint claude.ai is a legitimate AI service. The domains evil.example, other.example, and ais.example are clearly test placeholders. No network calls go to unexpected or suspicious domains.
The 455 code-smell findings are all low severity and concentrated in dist/ files. These are bundled dependencies. The scanner's YARA rules fire on minified JavaScript from webpack or esbuild output. A single bundled file can trigger dozens of matches from the libraries it contains. This is a known false positive pattern. The 142 IoC findings follow the same pattern. IoC extraction from bundled code produces noise. Property access chains, IPv6 fragments, and CDN domains inflate the count without indicating real risk.
The strongest counterargument is that the developer name "GitHub Actions" is unusual for an npm publisher, and the user count is zero. A new package with no users and a misleading publisher name could be a supply chain attack. However, the code itself shows no malicious behavior. The network calls match the documented API. The test fixtures are expected. There is no credential harvesting, no exfiltration architecture, no tool poisoning. The package does what it says it does.
The combination of zero tool poisoning, test-only secret findings, expected network endpoints, and bundled-dependency noise means this package is safe to use despite the high finding count.
Key Reasons
- Zero tool-poisoning findings across the entire package
- All 11 critical secret findings are in test files (dist/tests/) where hardcoded tokens are expected
- Network calls go to documented API endpoints (agentsandswarms.ai) matching the package's stated purpose
- 455 code-smell findings are in bundled dist/ files, a known false positive pattern
- No credential harvesting or exfiltration architecture detected
False Positive Considerations
- Bundled dependencies in dist/ files triggering 455 code-smell findings
- Test fixtures with hardcoded tokens in dist/tests/ files
- IoC extraction from bundled code producing 142 noise findings
- Test and example domains (evil.example, other.example) in network endpoints
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 82%.
MCP version history
Risk trend by version
9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace