MCP Registry

agentic-flow

by ruvnet
6a457b05-a010-561f-9055-6e10f4b1a2a3 | v2.1.3
100/ 100
CRITICAL risk
No change since v2.1.0
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.

Analysis record

Analysed
2 weeks ago
Version
v2.1.3
Artifact
SHA256 3A9…FB8
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 41 · highest severity first

YARA Rule Matches

13 rules
SeverityRuleHitsFilesMetadata
LOWspyeye 1
docs/benchmarks/optimization-guide.md
-
LOWUsingCommandLineArguments 59
dist/cli/config-wizard.js.mapdist/reasoningbank/hooks/pre-task.jsdist/proxy/anthropic-to-requesty.js +56 more
-
LOWDebuggerStatementsShouldNotBeUsed 15
.claude/commands/pair/examples.md.claude/commands/automation/self-healing.md.claude/agents/github/swarm-pr.md +12 more
-
LOWpostinstall file download 222
.claude/commands/github/project-board-sync.mddocs/plans/agent-booster/00-OVERVIEW.mddocs/archived/README_V1.1.11.md +219 more
-
LOWNoUseWeakRandom 54
dist/services/sona-service.js.mapdist/billing/metering/engine.js.mapdist/core/agentdb-wrapper.js.map +51 more
-
LOWNoUseEval 2
dist/utils/input-validator.jsdist/utils/input-validator.js.map
-
LOWSQLInjection 2
dist/workers/worker-benchmarks.jsdist/workers/worker-benchmarks.js.map
-
LOWcredential env files 234
dist/federation/integrations/supabase-adapter-debug.jsdist/router/providers/onnx.js.mapdist/mcp/fastmcp/tools/hooks/route.js +231 more
-
LOWpostinstall persistence mechanism 66
docs/plans/requesty/03-implementation-phases.mddocs/archived/ONNX_VS_CLAUDE_QUALITY.mddocs/supabase/migrations/001_create_federation_tables.sql +63 more
-
LOWpackage json suspicious scripts 1
docs/plans/agent-booster/04-NPM-SDK.md
-
LOWpostinstall obfuscation 74
dist/reasoningbank/prompts/distill-success.json.claude/settings-optimized.jsondist/federation/SecurityManager.d.ts +71 more
-
LOWpostinstall network communication 228
dist/swarm/p2p-swarm-v2.d.tsvalidation/test-quic-integration.tsdist/types/agentdb.js.map +225 more
-
LOWpostinstall crypto operations 1
dist/workers/ruvector-integration.d.ts
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

2,160 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

7
Secrets
26
Network
2,160
IoC Indicators

YARA Rules Matched

13 rules(959 hits)
spyeye UsingCommandLineArguments DebuggerStatementsShouldNotBeUsed postinstall file download NoUseWeakRandom NoUseEval SQLInjection credential env files postinstall persistence mechanism package json suspicious scripts postinstall obfuscation postinstall network communication postinstall crypto operations

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Tool-Poisoning Assessment

The evidence shows 8 tool-poisoning findings, but these are false positives from legitimate tool definitions. This package is an AI agent orchestration SDK that defines 213 MCP tools. Tool definitions in SDK libraries naturally contain description fields that scanners flag as potential poisoning. The finding count is small (8) relative to the 6896 total findings, and there is no evidence of hidden AI manipulation directives such as "do not tell the user," "silently execute," or XML-style instruction tags. Real tool poisoning contains DIRECTIVES aimed at the AI agent; this package contains DESCRIPTIONS aimed at developers.

Credential and Network Access

The 6 secret findings are not detailed in the evidence, but critically, there are NO credential-access findings targeting sensitive paths like .ssh/, .aws/credentials, .kube/config, or application_default_credentials.json. The network findings all originate from dist/ directory files (bundled/compiled code): dist/sdk/plugins.js:108, dist/swarm/p2p-swarm-v2.js:510, dist/proxy/quic-proxy.js:151, dist/proxy/anthropic-to-requesty.js:144, dist/services/embedding-service.js:108, dist/intelligence/agent-booster-enhanced.js:961, and dist/router/providers/openrouter.js:17. These file names indicate legitimate functionality: plugin systems, P2P swarm communication, QUIC proxy, Anthropic integration, embedding services, and OpenRouter provider. The exfiltration signal requires the COMBINATION of credential reads targeting secrets plus network calls to unknown domains. Neither condition is met here.

Strongest Counterargument

The developer "ruvnet" is an unknown publisher with 0 users, which increases suspicion in the MCP ecosystem. However, the finding NATURE does not support malicious intent. The 3614 IoC findings are SHA256 hashes without domain context (IoC extractor garbage). The 2588 malware-signature findings are from bundled dependencies in dist/ files. The 62 code-smell findings are noise from YARA rules matching basic Node.js patterns. None of these indicate actual malicious behavior.

Conclusion

This is a legitimate MCP SDK library. The massive finding volume (6896) is from bundled dependencies. No tool poisoning with hidden directives, no credential theft architecture, no suspicious network destinations. The package should be treated as likely_false_positive.

Key Reasons

  • Tool-poisoning findings are false positives from legitimate MCP tool definitions in SDK library
  • No credential-access findings targeting sensitive paths (.ssh, .aws, .kube)
  • Network calls are to expected services (OpenRouter, embedding services) from bundled dist/ files
  • 6896 total findings dominated by bundled dependency noise (3614 IoC, 2588 malware-signature)
  • No exfiltration architecture: no combination of secret reads + unknown domain calls

False Positive Considerations

  • Tool definitions in SDK code flagged as tool-poisoning
  • Bundled dependencies in dist/ directory generating IoC and malware-signature findings
  • IoC extractor noise (SHA256 hashes without domain context)
  • Code-smell YARA rules matching basic Node.js patterns

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 75%.

MCP version history

Risk trend by version

6 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
100
Change since first
+5
Change from previous
No change
Versions:
First analyzed version
2.0.8
May 5, 2026
Risk range
95 to 100
Across analyzed versions
Latest analyzed version
2.1.3
Sep 16, 2026
Selected version
critical
Version
v2.1.3
2 weeks ago
Risk score
100
Findings
5093
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

The agentic meta-harness — freeze the model, evolve the harness. An open runtime that routes each query to the cost-optimal model, evolves its own harness (planner/context/reviewer/retry/tool/memory/score policy) and autonomously repairs code, then orches

Frequently Asked Questions