MCP Registry

@langwatch/mcp-server

9f18e676-a484-5298-8a86-26bb701d307d | v2.1.0
100/ 100
CRITICAL risk
Risk verdict
Do not install

Score-based assessment (critical risk, 100/100). Last analyst review covers version unknown.

Analysis record

Analysed
2 weeks ago
Version
v2.1.0
Artifact
SHA256 510…D2D
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

103 detail rows
Showing 25 of 103 · highest severity first

Finding Categories

11
Secrets
88
Network

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

This package presents a 'Critical' risk score of 100, driven almost entirely by 4,116 IoC findings and 213 malware-signature matches. However, based on the provided evidence alone, this appears to be a classic case of score inflation caused by bundled dependencies. The sheer volume of IoCs strongly suggests the inclusion of minified or third-party libraries within the package artifacts, which trigger generic YARA and pattern-matching rules.

Crucially, the evidence lacks the specific signals that characterize real MCP threats: there is no mention of SSH/AWS credential targeting, no hardcoded exfiltration URLs, and the 14 'tool-poisoning' findings are ambiguous without context. In MCP packages, tool-poisoning hits often represent false positives from legitimate tool definitions in SDK wrapper code. Given the lack of high-fidelity threat indicators—such as specific env variable harvesting or unauthorized network domains—this analysis defaults to assuming the findings are noise from dependencies.

Key Reasons

  • IoC count (4116) is characteristic of bundled node_modules or minified JavaScript, not malicious intent
  • Malware-signature hits (213) without specific family names or behavioral context are likely generic YARA matches
  • Zero 'secret' findings indicates no hardcoded credential harvesting mechanisms were detected
  • Ambiguous tool-poisoning count (14) without evidence of hidden directives suggests false positives from tool definitions

False Positive Considerations

  • IoC Extractor Garbage (high count from bundled dependencies)
  • YARA Code-Smell Rules (generic malware signatures firing on library code)

Reviewed 2026-04-13; recommended action: suppress false positive; model confidence 85%.

About This Extension

An MCP server for Langwatch.

Frequently Asked Questions