The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v3.12.0
- Artifact
- SHA256 64A…CB1
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
11 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 12 | util.jssrc/options.tscode-tool.js +9 more | - |
| LOW | postinstall file download | 29 | src/instructions.tscode-tool.mjscode-tool-worker.mjs +26 more | - |
| LOW | NoUseEval | 3 | code-tool-worker.jscode-tool-worker.mjssrc/code-tool-worker.ts | - |
| LOW | UsingCommandLineArguments | 1 | src/options.ts | - |
| LOW | postinstall file manipulation | 25 | instructions.mjsoptions.mjsmethods.d.mts +22 more | - |
| LOW | postinstall system command | 32 | src/local-docs-search.tscode-tool-worker.mjscode-tool.js +29 more | - |
| LOW | postinstall environment access | 15 | methods.d.mtsoptions.d.tssrc/stdio.ts +12 more | - |
| LOW | postinstall obfuscation | 22 | code-tool-worker.mjsutil.jsutil.d.mts +19 more | - |
| LOW | postinstall network communication | 27 | code-tool-worker.mjsindex.mjssrc/options.ts +24 more | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 3 | code-tool.jssrc/code-tool.tscode-tool.mjs | - |
| LOW | postinstall crypto operations | 6 | src/local-docs-search.tslocal-docs-search.jslocal-docs-search.mjs +3 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
11 rules(175 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Tool-Poisoning Assessment
The package has 1 tool-poisoning finding in the evidence. This is almost certainly a false positive from legitimate tool definitions. The package description states it is "The official MCP Server for the Plumery API," and the file paths show legitimate tool files like src/code-tool.ts and docs-search-tool.js. These are tool definition files that describe what the tools do, not hidden AI manipulation directives. Real tool poisoning contains explicit instructions like "do not tell the user" or "silently execute" embedded in tool descriptions. The evidence does not show any such hidden directives—only standard tool registration code.
Credential and Network Access
The package has 6 secret findings and 8 network findings. The network findings are legitimate API calls: src/code-tool.ts:152, docs-search-tool.js:69, and src/instructions.ts:62 all contain fetch calls to the Plumery API, which is the documented purpose of this MCP server. There is no evidence of credential exfiltration to unknown domains. The secret findings likely reference API key configuration for connecting to the Plumery API, which is normal for an MCP server that needs to authenticate with its target service. No credential-access findings target sensitive paths like .ssh/, .aws/credentials, or .kube/config.
IoC Findings
The 142 IoC findings are entirely false positives from the known IoC extractor garbage pattern. The detected "domains" are property access chains and file references: this.proseindex.search, methods.map, code-tool-types.d.ts.map, code-tool-types.js.map, code-tool-types.mjs.map, code-tool-worker.d.mts.map, parties.cards, parties.loans, and parties.individuals.tax are all JavaScript object properties and source map files, not network destinations. The IoC extractor misreads these as domains.
Malware Signatures
The 172 malware-signature findings are from bundled dependencies in dist/ files. This is expected behavior for any non-trivial JavaScript package with npm dependencies. The code-smell findings (6 total) are also noise from generic patterns.
Strongest Counterargument
The strongest counterargument is that the package has 488 total findings with 174 high-severity and 7 critical-severity items. However, the severity scoring is inflated by the known false-positive patterns. The high-severity count comes from malware signatures (172) which are from bundled code, not malicious behavior. The critical findings are likely from code-smell rules or generic credential-access patterns, not actual credential theft.
Conclusion
This is a legitimate MCP server for the Plumery API with false-positive findings from known noise sources. The tool-poisoning finding is from tool definitions, not hidden AI directives. The network calls are legitimate API calls. The IoC findings are property access chains misread as domains. The malware signatures are from bundled dependencies.
Key Reasons
- IoC findings are property access chains and source map files misread as domains
- Tool-poisoning finding is from legitimate tool definitions, not hidden AI directives
- Network calls are to documented Plumery API endpoints, not unknown exfiltration domains
- Malware signatures are from bundled npm dependencies in dist/ files
- No credential-access findings target sensitive paths like .ssh or .aws
False Positive Considerations
- IoC extractor misreading property chains as domains
- Bundled dependencies triggering malware signatures
- Tool definitions flagged as tool-poisoning
- Code-smell rules matching generic patterns
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 80%.
MCP version history
Risk trend by version
8 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace