MCP Registry

@ripla/godd-mcp

83a08ab7-77d0-5dff-95fc-98575a1a079e | v1.0.7
100/ 100
CRITICAL risk
+2 since v1.0.6
Risk verdict
Do not install

Score-based assessment (critical risk, 100/100). Last analyst review covers version unknown.

Analysis record

Analysed
1 weeks ago
Version
v1.0.7
Artifact
SHA256 925…DA2
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

22 detail rows

Finding Categories

8
Secrets
8
Network

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

This package presents a critical risk score of 100 based on volume alone, with 2,030 IoC findings and 237 malware signatures. However, this pattern is a textbook false-positive profile for MCP servers containing bundled JavaScript dependencies. The scanner has detected zero instances of tool poisoning, zero secret exposure, and only three generic network findings. The "malware" signatures are likely legacy YARA rules (e.g., Surtr, Bolonyokte) firing on generic configuration strings or minified code within the bundle. The high IoC count consists primarily of property access chains (b.call, h.next), IPv6 fragments, and CDNs misidentified as network threats. There is no evidence of environment variable exfiltration, no tool result interception, and no mismatch between the package's stated purpose (encrypted prompt distribution) and the lack of specific threat indicators. The 'CRITICAL' rating appears to be a score inflation artifact, not a reflection of actual malicious behavior.

Key Reasons

  • Zero tool-poisoning findings despite 2,500+ total matches
  • No credential-access or secret-exposure findings
  • IoC and signature counts consistent with bundled dependencies causing false positives
  • Absence of suspicious network domains (only 3 generic findings)

False Positive Considerations

  • Bundled dependencies (dist/ files)
  • YARA code-smell rules (generic malware families)
  • IoC extractor garbage (property chains, hex strings)

Reviewed 2026-04-12; recommended action: suppress false positive; model confidence 85%.

MCP version history

Risk trend by version

5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
100
Change since first
No change
Change from previous
+2
Versions:
First analyzed version
1.0.3
May 14, 2026
Risk range
98 to 100
Across analyzed versions
Latest analyzed version
1.0.7
Sep 18, 2026
Selected version
critical
Version
v1.0.7
1 weeks ago
Risk score
100
Findings
22
Change vs previous
+2

Pick any point on the chart to explore that version's code below.

About This Extension

GoDD MCP Server - AI-powered development workflow tools via Model Context Protocol (slash commands support)

Frequently Asked Questions