The AI review rates the findings as likely false positive, but the risk score (72/100) still counts them.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v1.16.2
- Artifact
- SHA256 02D…1E4
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
10 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 9 | dist/proof/verifier.d.tsdist/types/protocol.d.tsdist/types/protocol.js +6 more | - |
| LOW | postinstall persistence mechanism | 6 | dist/audit/service.d.tsdist/audit/assurance.d.tsdist/audit/assurance.js +3 more | - |
| LOW | postinstall file download | 70 | dist/providers/runtime-fetch.js.mapdist/card/resolve.d.tsdist/providers/system-clock.d.ts +67 more | - |
| LOW | postinstall registry modification | 28 | dist/authz/index.jsdist/authz/registry.d.ts.mapdist/middleware/with-kya-os.delegation-verify.js +25 more | - |
| LOW | postinstall obfuscation | 103 | dist/utils/base58.jsdist/card/delegation.d.tsdist/session/manager.js +100 more | - |
| LOW | postinstall crypto operations | 147 | dist/providers/memory.d.tsdist/providers/index.jsdist/providers/audit-log.d.ts +144 more | - |
| LOW | postinstall system command | 44 | schemas/kya-os-card.schema.jsondist/card/delegation.jsdist/policy/classifier.js +41 more | - |
| LOW | postinstall network communication | 36 | dist/utils/safe-fetch-transports.jsschemas/kya-os-card.schema.jsondist/utils/safe-fetch.js +33 more | - |
| LOW | postinstall environment access | 13 | dist/audit/schemas.d.tsdist/audit/schemas.jsdist/integrations/cheqd/registrar.js +10 more | - |
| LOW | postinstall file manipulation | 49 | dist/delegation/delegation-graph.jsdist/policy/classifier.d.tsdist/middleware/with-kya-os.config-types.d.ts +46 more | - |
Finding Categories
YARA Rules Matched
10 rules(505 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Tool Poisoning Assessment
Zero tool-poisoning findings were detected. This is the most critical threat indicator for MCP packages, and its complete absence is a strong signal of benign code. The findings summary explicitly shows "tool-poisoning":"0" with no hidden AI manipulation directives, XML-style instruction tags, or invisible Unicode characters encoding covert instructions.
Credential and Network Access
The package has zero credential-access findings and zero secret findings. It does not read sensitive paths like .ssh/, .aws/credentials, .kube/config, or target specific secret names such as GITHUB_TOKEN or AWS_SECRET_ACCESS_KEY. The 8 network findings are all NET-FETCH calls in the dist/ folder (bundled code), specifically in dist/delegation/did-web-resolver.js and dist/providers/base.d.ts. These are legitimate fetch calls for DID (Decentralized Identifier) web resolution, which aligns with the package's stated purpose as a "KYA-OS protocol for Model Context Protocol servers: delegation, proof, and session primitives."
IoC Findings Are Noise
The 174 IoC findings are classic false positives from the XIOC extractor. Examples include:
XIOC-DOMAIN-protocol.d.ts.mapandXIOC-DOMAIN-crypto-service.js.map— source map files misidentified as domainsXIOC-EMAIL-ended@${finaldelegation.id— a template string, not a real emailXIOC-URL-https://keepachangelog.com/en/1.0.0/andXIOC-URL-https://semver.org/spec/v2.0.0.html— documentation URLsXIOC-DOMAIN-schema.modelcontextprotocol-identity.io— a legitimate schema domain for MCP identity
None of these represent suspicious external domains for exfiltration. The IoC extractor is matching .js.map and .d.ts.map file extensions as "domains," which is documented noise.
Strongest Counterargument
The anonymous developer name "h0bb5" and zero user count could suggest an unvetted package. However, the absence of any actual malicious patterns (no tool poisoning, no credential theft, no malware signatures, no obfuscation) outweighs this concern. The package implements a legitimate protocol (KYA-OS for MCP delegation and identity), and all findings are explainable as scanner noise on source maps and documentation references.
Conclusion
This package exhibits no evidence of malicious intent. The 192 total findings are entirely attributable to IoC extractor false positives on source map files and benign documentation URLs, combined with legitimate network calls in DID resolver code. The zero tool-poisoning and zero credential-access counts are definitive indicators of a benign implementation.
Key Reasons
- Zero tool-poisoning findings (the defining MCP threat)
- Zero credential-access and zero secret findings
- All IoC findings are false positives from source map files and documentation URLs
- Network calls are in legitimate DID web resolver code
- Zero malware signatures and zero obfuscation findings
False Positive Considerations
- XIOC extractor matching .js.map and .d.ts.map files as domains
- Documentation URLs (keepachangelog.com, semver.org) flagged as IoCs
- Template strings misidentified as email addresses
- Bundled dist/ folder triggering network findings on legitimate fetch calls
Reviewed 2026-05-25; recommended action: suppress false positive; model confidence 85%.
MCP version history
Risk trend by version
15 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace