The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v2.1.3
- Artifact
- SHA256 3A9…FB8
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
13 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | spyeye | 1 | docs/benchmarks/optimization-guide.md | - |
| LOW | UsingCommandLineArguments | 59 | dist/utils/cli.js.mapdist/billing/cli.js.mapdist/proxy/anthropic-to-requesty.js +56 more | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 15 | .claude/commands/pair/examples.md.claude/commands/automation/self-healing.md.claude/commands/sparc/debugger.md +12 more | - |
| LOW | postinstall file download | 222 | docs/plans/agent-booster/00-OVERVIEW.mddocs/architecture/RESEARCH_SUMMARY.md.claude/agents/github/project-board-sync.md +219 more | - |
| LOW | NoUseWeakRandom | 54 | dist/billing/payments/processor.jsdist/core/agentdb-wrapper.jsdist/billing/coupons/manager.js +51 more | - |
| LOW | NoUseEval | 2 | dist/utils/input-validator.jsdist/utils/input-validator.js.map | - |
| LOW | SQLInjection | 2 | dist/workers/worker-benchmarks.jsdist/workers/worker-benchmarks.js.map | - |
| LOW | credential env files | 234 | validation/test-provider-fallback.tsdist/federation/integrations/realtime-federation.js.mapdist/utils/agentdb-runtime-patch.js +231 more | - |
| LOW | postinstall persistence mechanism | 66 | docs/archived/MODEL_VALIDATION_REPORT.mddocs/plans/agent-booster/03-BENCHMARKS.mddocs/archived/OPENROUTER_VALIDATION_COMPLETE.md +63 more | - |
| LOW | package json suspicious scripts | 1 | docs/plans/agent-booster/04-NPM-SDK.md | - |
| LOW | postinstall obfuscation | 74 | dist/router/providers/onnx-local.jsdist/embeddings/neural-substrate.js.map.claude/agents/github/swarm-pr.md +71 more | - |
| LOW | postinstall network communication | 228 | dist/workers/ruvector-integration.jsdocs/guides/STANDALONE_PROXY_GUIDE.mddocs/integration-docs/INTEGRATION-QUICK-SUMMARY.md +225 more | - |
| LOW | postinstall crypto operations | 1 | dist/mcp/fastmcp/tools/hooks/intelligence-bridge.js.map | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
13 rules(959 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Tool-Poisoning Assessment
The evidence shows 8 tool-poisoning findings, but these are false positives from legitimate tool definitions. This package is an AI agent orchestration SDK that defines 213 MCP tools. Tool definitions in SDK libraries naturally contain description fields that scanners flag as potential poisoning. The finding count is small (8) relative to the 6896 total findings, and there is no evidence of hidden AI manipulation directives such as "do not tell the user," "silently execute," or XML-style instruction tags. Real tool poisoning contains DIRECTIVES aimed at the AI agent; this package contains DESCRIPTIONS aimed at developers.
Credential and Network Access
The 6 secret findings are not detailed in the evidence, but critically, there are NO credential-access findings targeting sensitive paths like .ssh/, .aws/credentials, .kube/config, or application_default_credentials.json. The network findings all originate from dist/ directory files (bundled/compiled code): dist/sdk/plugins.js:108, dist/swarm/p2p-swarm-v2.js:510, dist/proxy/quic-proxy.js:151, dist/proxy/anthropic-to-requesty.js:144, dist/services/embedding-service.js:108, dist/intelligence/agent-booster-enhanced.js:961, and dist/router/providers/openrouter.js:17. These file names indicate legitimate functionality: plugin systems, P2P swarm communication, QUIC proxy, Anthropic integration, embedding services, and OpenRouter provider. The exfiltration signal requires the COMBINATION of credential reads targeting secrets plus network calls to unknown domains. Neither condition is met here.
Strongest Counterargument
The developer "ruvnet" is an unknown publisher with 0 users, which increases suspicion in the MCP ecosystem. However, the finding NATURE does not support malicious intent. The 3614 IoC findings are SHA256 hashes without domain context (IoC extractor garbage). The 2588 malware-signature findings are from bundled dependencies in dist/ files. The 62 code-smell findings are noise from YARA rules matching basic Node.js patterns. None of these indicate actual malicious behavior.
Conclusion
This is a legitimate MCP SDK library. The massive finding volume (6896) is from bundled dependencies. No tool poisoning with hidden directives, no credential theft architecture, no suspicious network destinations. The package should be treated as likely_false_positive.
Key Reasons
- Tool-poisoning findings are false positives from legitimate MCP tool definitions in SDK library
- No credential-access findings targeting sensitive paths (.ssh, .aws, .kube)
- Network calls are to expected services (OpenRouter, embedding services) from bundled dist/ files
- 6896 total findings dominated by bundled dependency noise (3614 IoC, 2588 malware-signature)
- No exfiltration architecture: no combination of secret reads + unknown domain calls
False Positive Considerations
- Tool definitions in SDK code flagged as tool-poisoning
- Bundled dependencies in dist/ directory generating IoC and malware-signature findings
- IoC extractor noise (SHA256 hashes without domain context)
- Code-smell YARA rules matching basic Node.js patterns
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 75%.
MCP version history
Risk trend by version
6 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace