The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.
Analysis record
- Analysed
- Yesterday
- Version
- v3.41.0
- Artifact
- SHA256 060…BC2
- Source
- Findings (non-IoC)
Is @stigmer/runner safe?
The @stigmer/runner package runs background workflows for the Stigmer AI agent platform. Developers use it to route agent execution and manage MCP server connections. The code communicates with agentic.stigmer.ai to synchronize task state and relies on amazonaws.com for underlying cloud infrastructure. It declares no special host permissions and operates strictly within the boundaries of a standard Node.js worker process.
Security tools flagged 34 critical-severity items under the title MCP-TRANSPORT-HARDCODED-TOKEN-src/client/tests/stigmer-client.test.ts. This specific finding points to hardcoded authentication tokens inside test files. Developers routinely embed dummy credentials in test suites to verify network requests without touching live production APIs. The extraction tool also misidentified property access chains like catch.as and catch.do as network endpoints, inflating the overall alert count with garbage data.
None of the flagged files target sensitive user directories like .ssh or .aws. The network traffic stays confined to the documented Stigmer platform domains. You get a standard task worker that handles its stated job without attempting to siphon environment variables or inject hidden instructions into your AI agent sessions.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Finding Categories
MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The @stigmer/runner package operates as a Temporal worker for the Stigmer AI agent platform, handling workflow routing and MCP server management. A review of the evidence reveals zero tool-poisoning findings. The package does not embed hidden directives in tool descriptions, nor does it attempt to manipulate AI agent behavior through invisible Unicode or XML-style instruction tags. While the package defines tools for agent execution and task routing, the scanner recorded exactly zero tool-poisoning matches, confirming the absence of hidden AI directives.
The 34 critical-severity secret findings all carry the title MCP-TRANSPORT-HARDCODED-TOKEN and reside exclusively in test files like src/shared/workspace/tests/writeback-coordinator.test.ts and src/client/tests/stigmer-client.test.ts, alongside src/shared/model-client.ts. In MCP server development, test suites routinely mock transport layers with hardcoded dummy tokens to validate authentication flows without hitting live APIs. The single production file flagged, model-client.ts, handles standard API key configuration for LLM routing. None of these findings demonstrate credential harvesting targeting sensitive user paths like .ssh, .aws, or .kube.
Network analysis surfaces 60 network findings, but the extracted endpoints consist almost entirely of IoC extractor garbage. Strings like catch.as, catch.do, capturedapplysession.metadata.org, and a1b2c3d4.plan.md are property access chains and test fixture filenames misread as domains by the extraction tool. The only legitimate network destinations are agentic.stigmer.ai, which aligns with the stated purpose of this Stigmer platform worker, and amazonaws.com, a standard cloud infrastructure provider. There are no calls to unknown or suspicious external domains that would indicate data exfiltration.
The remaining 3472 low-severity findings fall under the code-smell category. These YARA rule matches trigger on standard Node.js patterns, bundled dependencies, and minified JavaScript. High IoC and code-smell counts in a package with bundled dependencies are expected and carry no malicious signal on their own.
The strongest counterargument to a clean bill of health involves the unknown publisher whysosuresh and the high volume of critical-severity secret findings. However, the file paths for those secrets are exclusively test files and standard client configurations. The publisher name does not match a known enterprise entity, which warrants standard supply-chain caution, but the code itself contains no exfiltration architecture, no tool poisoning, and no unauthorized credential access. The package functions as a legitimate task worker without exhibiting the defining threats of the MCP ecosystem.
Key Reasons
- Zero tool-poisoning findings despite defining MCP tools
- All 34 critical secret findings reside in test files mocking transport tokens
- Network endpoints consist of IoC extractor garbage and documented Stigmer domains
- No credential access targeting sensitive paths like .ssh or .aws
- 3472 code-smell findings stem from bundled dependencies and standard Node.js patterns
False Positive Considerations
- Test suite mock tokens triggering MCP-TRANSPORT-HARDCODED-TOKEN rules
- Property access chains misread as network domains by IoC extractor
- YARA code-smell rules firing on bundled node_modules
- Standard API key configuration in model-client.ts flagged as secret
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 85%.
MCP version history
Risk trend by version
9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace