MCP Registry

@kya-os/mcp

by h0bb5
6a13cef8-b0f1-514d-84ea-3346ff09cb67 | v1.16.2
72/ 100
HIGH risk
-3 since v1.16.1
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (72/100) still counts them.

Analysis record

Analysed
1 weeks ago
Version
v1.16.2
Artifact
SHA256 02D…1E4
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

530 detail rows

YARA Rule Matches

10 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 9
dist/proof/verifier.d.tsdist/types/protocol.d.tsdist/types/protocol.js +6 more
-
LOWpostinstall persistence mechanism 6
dist/audit/service.d.tsdist/audit/assurance.d.tsdist/audit/assurance.js +3 more
-
LOWpostinstall file download 70
dist/providers/runtime-fetch.js.mapdist/card/resolve.d.tsdist/providers/system-clock.d.ts +67 more
-
LOWpostinstall registry modification 28
dist/authz/index.jsdist/authz/registry.d.ts.mapdist/middleware/with-kya-os.delegation-verify.js +25 more
-
LOWpostinstall obfuscation 103
dist/utils/base58.jsdist/card/delegation.d.tsdist/session/manager.js +100 more
-
LOWpostinstall crypto operations 147
dist/providers/memory.d.tsdist/providers/index.jsdist/providers/audit-log.d.ts +144 more
-
LOWpostinstall system command 44
schemas/kya-os-card.schema.jsondist/card/delegation.jsdist/policy/classifier.js +41 more
-
LOWpostinstall network communication 36
dist/utils/safe-fetch-transports.jsschemas/kya-os-card.schema.jsondist/utils/safe-fetch.js +33 more
-
LOWpostinstall environment access 13
dist/audit/schemas.d.tsdist/audit/schemas.jsdist/integrations/cheqd/registrar.js +10 more
-
LOWpostinstall file manipulation 49
dist/delegation/delegation-graph.jsdist/policy/classifier.d.tsdist/middleware/with-kya-os.config-types.d.ts +46 more
-

Finding Categories

1
Secrets
24
Network

YARA Rules Matched

10 rules(505 hits)
credential env files postinstall persistence mechanism postinstall file download postinstall registry modification postinstall obfuscation postinstall crypto operations postinstall system command postinstall network communication postinstall environment access postinstall file manipulation

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Tool Poisoning Assessment

Zero tool-poisoning findings were detected. This is the most critical threat indicator for MCP packages, and its complete absence is a strong signal of benign code. The findings summary explicitly shows "tool-poisoning":"0" with no hidden AI manipulation directives, XML-style instruction tags, or invisible Unicode characters encoding covert instructions.

Credential and Network Access

The package has zero credential-access findings and zero secret findings. It does not read sensitive paths like .ssh/, .aws/credentials, .kube/config, or target specific secret names such as GITHUB_TOKEN or AWS_SECRET_ACCESS_KEY. The 8 network findings are all NET-FETCH calls in the dist/ folder (bundled code), specifically in dist/delegation/did-web-resolver.js and dist/providers/base.d.ts. These are legitimate fetch calls for DID (Decentralized Identifier) web resolution, which aligns with the package's stated purpose as a "KYA-OS protocol for Model Context Protocol servers: delegation, proof, and session primitives."

IoC Findings Are Noise

The 174 IoC findings are classic false positives from the XIOC extractor. Examples include:

  • XIOC-DOMAIN-protocol.d.ts.map and XIOC-DOMAIN-crypto-service.js.map — source map files misidentified as domains
  • XIOC-EMAIL-ended@${finaldelegation.id — a template string, not a real email
  • XIOC-URL-https://keepachangelog.com/en/1.0.0/ and XIOC-URL-https://semver.org/spec/v2.0.0.html — documentation URLs
  • XIOC-DOMAIN-schema.modelcontextprotocol-identity.io — a legitimate schema domain for MCP identity

None of these represent suspicious external domains for exfiltration. The IoC extractor is matching .js.map and .d.ts.map file extensions as "domains," which is documented noise.

Strongest Counterargument

The anonymous developer name "h0bb5" and zero user count could suggest an unvetted package. However, the absence of any actual malicious patterns (no tool poisoning, no credential theft, no malware signatures, no obfuscation) outweighs this concern. The package implements a legitimate protocol (KYA-OS for MCP delegation and identity), and all findings are explainable as scanner noise on source maps and documentation references.

Conclusion

This package exhibits no evidence of malicious intent. The 192 total findings are entirely attributable to IoC extractor false positives on source map files and benign documentation URLs, combined with legitimate network calls in DID resolver code. The zero tool-poisoning and zero credential-access counts are definitive indicators of a benign implementation.

Key Reasons

  • Zero tool-poisoning findings (the defining MCP threat)
  • Zero credential-access and zero secret findings
  • All IoC findings are false positives from source map files and documentation URLs
  • Network calls are in legitimate DID web resolver code
  • Zero malware signatures and zero obfuscation findings

False Positive Considerations

  • XIOC extractor matching .js.map and .d.ts.map files as domains
  • Documentation URLs (keepachangelog.com, semver.org) flagged as IoCs
  • Template strings misidentified as email addresses
  • Bundled dist/ folder triggering network findings on legitimate fetch calls

Reviewed 2026-05-25; recommended action: suppress false positive; model confidence 85%.

MCP version history

Risk trend by version

15 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
72
Change since first
+24
Change from previous
-3
Versions:
First analyzed version
1.2.0
May 15, 2026
Risk range
48 to 75
Across analyzed versions
Latest analyzed version
1.16.2
Sep 21, 2026
Selected version
high
Version
v1.16.2
1 weeks ago
Risk score
72
Findings
530
Change vs previous
-3

Pick any point on the chart to explore that version's code below.

About This Extension

Reference implementation of the KYA-OS protocol for Model Context Protocol servers: identity, delegation, proofs, sessions, and verifiable audit trails

Frequently Asked Questions