MCP Registry

@stigmer/runner

87471e68-15de-5449-ba1a-80a2dd799f88 | v3.41.0
100/ 100
CRITICAL risk
No change since v3.40.1
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.

Analysis record

Analysed
Yesterday
Version
v3.41.0
Artifact
SHA256 060…BC2
Source
Findings (non-IoC)

Is @stigmer/runner safe?

The @stigmer/runner package runs background workflows for the Stigmer AI agent platform. Developers use it to route agent execution and manage MCP server connections. The code communicates with agentic.stigmer.ai to synchronize task state and relies on amazonaws.com for underlying cloud infrastructure. It declares no special host permissions and operates strictly within the boundaries of a standard Node.js worker process.

Security tools flagged 34 critical-severity items under the title MCP-TRANSPORT-HARDCODED-TOKEN-src/client/tests/stigmer-client.test.ts. This specific finding points to hardcoded authentication tokens inside test files. Developers routinely embed dummy credentials in test suites to verify network requests without touching live production APIs. The extraction tool also misidentified property access chains like catch.as and catch.do as network endpoints, inflating the overall alert count with garbage data.

None of the flagged files target sensitive user directories like .ssh or .aws. The network traffic stays confined to the documented Stigmer platform domains. You get a standard task worker that handles its stated job without attempting to siphon environment variables or inject hidden instructions into your AI agent sessions.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

34 detail rows
Showing 25 of 34 · highest severity first

Finding Categories

34
Secrets

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The @stigmer/runner package operates as a Temporal worker for the Stigmer AI agent platform, handling workflow routing and MCP server management. A review of the evidence reveals zero tool-poisoning findings. The package does not embed hidden directives in tool descriptions, nor does it attempt to manipulate AI agent behavior through invisible Unicode or XML-style instruction tags. While the package defines tools for agent execution and task routing, the scanner recorded exactly zero tool-poisoning matches, confirming the absence of hidden AI directives.

The 34 critical-severity secret findings all carry the title MCP-TRANSPORT-HARDCODED-TOKEN and reside exclusively in test files like src/shared/workspace/tests/writeback-coordinator.test.ts and src/client/tests/stigmer-client.test.ts, alongside src/shared/model-client.ts. In MCP server development, test suites routinely mock transport layers with hardcoded dummy tokens to validate authentication flows without hitting live APIs. The single production file flagged, model-client.ts, handles standard API key configuration for LLM routing. None of these findings demonstrate credential harvesting targeting sensitive user paths like .ssh, .aws, or .kube.

Network analysis surfaces 60 network findings, but the extracted endpoints consist almost entirely of IoC extractor garbage. Strings like catch.as, catch.do, capturedapplysession.metadata.org, and a1b2c3d4.plan.md are property access chains and test fixture filenames misread as domains by the extraction tool. The only legitimate network destinations are agentic.stigmer.ai, which aligns with the stated purpose of this Stigmer platform worker, and amazonaws.com, a standard cloud infrastructure provider. There are no calls to unknown or suspicious external domains that would indicate data exfiltration.

The remaining 3472 low-severity findings fall under the code-smell category. These YARA rule matches trigger on standard Node.js patterns, bundled dependencies, and minified JavaScript. High IoC and code-smell counts in a package with bundled dependencies are expected and carry no malicious signal on their own.

The strongest counterargument to a clean bill of health involves the unknown publisher whysosuresh and the high volume of critical-severity secret findings. However, the file paths for those secrets are exclusively test files and standard client configurations. The publisher name does not match a known enterprise entity, which warrants standard supply-chain caution, but the code itself contains no exfiltration architecture, no tool poisoning, and no unauthorized credential access. The package functions as a legitimate task worker without exhibiting the defining threats of the MCP ecosystem.

Key Reasons

  • Zero tool-poisoning findings despite defining MCP tools
  • All 34 critical secret findings reside in test files mocking transport tokens
  • Network endpoints consist of IoC extractor garbage and documented Stigmer domains
  • No credential access targeting sensitive paths like .ssh or .aws
  • 3472 code-smell findings stem from bundled dependencies and standard Node.js patterns

False Positive Considerations

  • Test suite mock tokens triggering MCP-TRANSPORT-HARDCODED-TOKEN rules
  • Property access chains misread as network domains by IoC extractor
  • YARA code-smell rules firing on bundled node_modules
  • Standard API key configuration in model-client.ts flagged as secret

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 85%.

MCP version history

Risk trend by version

9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
100
Change since first
+8
Change from previous
No change
Versions:
First analyzed version
3.0.8
Jun 29, 2026
Risk range
92 to 100
Across analyzed versions
Latest analyzed version
3.41.0
Sep 30, 2026
Selected version
critical
Version
v3.41.0
Yesterday
Risk score
100
Findings
4025
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Embeddable Temporal worker for the Stigmer AI agent platform — handles agent execution, workflow orchestration, and MCP server management

Frequently Asked Questions