MCP Registry

plumery-mcp

877b0434-aff8-5bd0-8b69-877d0d1f2a02 | v3.12.0
100/ 100
CRITICAL risk
No change since v3.11.0
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.

Analysis record

Analysed
1 weeks ago
Version
v3.12.0
Artifact
SHA256 64A…CB1
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

204 detail rows
Showing 25 of 29 · highest severity first

YARA Rule Matches

11 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 12
util.jssrc/options.tscode-tool.js +9 more
-
LOWpostinstall file download 29
src/instructions.tscode-tool.mjscode-tool-worker.mjs +26 more
-
LOWNoUseEval 3
code-tool-worker.jscode-tool-worker.mjssrc/code-tool-worker.ts
-
LOWUsingCommandLineArguments 1
src/options.ts
-
LOWpostinstall file manipulation 25
instructions.mjsoptions.mjsmethods.d.mts +22 more
-
LOWpostinstall system command 32
src/local-docs-search.tscode-tool-worker.mjscode-tool.js +29 more
-
LOWpostinstall environment access 15
methods.d.mtsoptions.d.tssrc/stdio.ts +12 more
-
LOWpostinstall obfuscation 22
code-tool-worker.mjsutil.jsutil.d.mts +19 more
-
LOWpostinstall network communication 27
code-tool-worker.mjsindex.mjssrc/options.ts +24 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 3
code-tool.jssrc/code-tool.tscode-tool.mjs
-
LOWpostinstall crypto operations 6
src/local-docs-search.tslocal-docs-search.jslocal-docs-search.mjs +3 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

218 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

18
Secrets
10
Network
218
IoC Indicators

YARA Rules Matched

11 rules(175 hits)
credential env files postinstall file download NoUseEval UsingCommandLineArguments postinstall file manipulation postinstall system command postinstall environment access postinstall obfuscation postinstall network communication UsingShellInterpreterWhenExecutingOSCommands postinstall crypto operations

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Tool-Poisoning Assessment

The package has 1 tool-poisoning finding in the evidence. This is almost certainly a false positive from legitimate tool definitions. The package description states it is "The official MCP Server for the Plumery API," and the file paths show legitimate tool files like src/code-tool.ts and docs-search-tool.js. These are tool definition files that describe what the tools do, not hidden AI manipulation directives. Real tool poisoning contains explicit instructions like "do not tell the user" or "silently execute" embedded in tool descriptions. The evidence does not show any such hidden directives—only standard tool registration code.

Credential and Network Access

The package has 6 secret findings and 8 network findings. The network findings are legitimate API calls: src/code-tool.ts:152, docs-search-tool.js:69, and src/instructions.ts:62 all contain fetch calls to the Plumery API, which is the documented purpose of this MCP server. There is no evidence of credential exfiltration to unknown domains. The secret findings likely reference API key configuration for connecting to the Plumery API, which is normal for an MCP server that needs to authenticate with its target service. No credential-access findings target sensitive paths like .ssh/, .aws/credentials, or .kube/config.

IoC Findings

The 142 IoC findings are entirely false positives from the known IoC extractor garbage pattern. The detected "domains" are property access chains and file references: this.proseindex.search, methods.map, code-tool-types.d.ts.map, code-tool-types.js.map, code-tool-types.mjs.map, code-tool-worker.d.mts.map, parties.cards, parties.loans, and parties.individuals.tax are all JavaScript object properties and source map files, not network destinations. The IoC extractor misreads these as domains.

Malware Signatures

The 172 malware-signature findings are from bundled dependencies in dist/ files. This is expected behavior for any non-trivial JavaScript package with npm dependencies. The code-smell findings (6 total) are also noise from generic patterns.

Strongest Counterargument

The strongest counterargument is that the package has 488 total findings with 174 high-severity and 7 critical-severity items. However, the severity scoring is inflated by the known false-positive patterns. The high-severity count comes from malware signatures (172) which are from bundled code, not malicious behavior. The critical findings are likely from code-smell rules or generic credential-access patterns, not actual credential theft.

Conclusion

This is a legitimate MCP server for the Plumery API with false-positive findings from known noise sources. The tool-poisoning finding is from tool definitions, not hidden AI directives. The network calls are legitimate API calls. The IoC findings are property access chains misread as domains. The malware signatures are from bundled dependencies.

Key Reasons

  • IoC findings are property access chains and source map files misread as domains
  • Tool-poisoning finding is from legitimate tool definitions, not hidden AI directives
  • Network calls are to documented Plumery API endpoints, not unknown exfiltration domains
  • Malware signatures are from bundled npm dependencies in dist/ files
  • No credential-access findings target sensitive paths like .ssh or .aws

False Positive Considerations

  • IoC extractor misreading property chains as domains
  • Bundled dependencies triggering malware signatures
  • Tool definitions flagged as tool-poisoning
  • Code-smell rules matching generic patterns

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 80%.

MCP version history

Risk trend by version

8 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
100
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
3.5.0
Apr 30, 2026
Risk range
98 to 100
Across analyzed versions
Latest analyzed version
3.12.0
Sep 18, 2026
Selected version
critical
Version
v3.12.0
1 weeks ago
Risk score
100
Findings
422
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

The official MCP Server for the Plumery API

Frequently Asked Questions