MCP Registry

zipline-mcp

a7e1772d-b4e4-5a37-a3dd-8601dfc60b20 | v1.12.24
100/ 100
CRITICAL risk
No change since v1.12.23
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v1.12.24
Artifact
SHA256 F75…A36
Source
Findings (non-IoC)

Is zipline-mcp safe?

zipline-mcp is an MCP server that uploads files to Zipline-compatible hosting services. The package makes network calls through dist/index.js, dist/userFiles.js, and dist/remoteFolders.js to reach hosts like zipline.diced.sh, which is a real public Zipline instance. It declares no special permissions and no host permissions in its manifest.

The scanner flagged one tool-poisoning match at dist/index.js:458. That line lives in the section of code where the package registers its upload tools, and tool descriptions are exactly what the scanner looks for when it hunts hidden AI instructions. Nine hardcoded-token findings all sit inside .test.js files where fake credentials belong. Neither category of finding reaches into production code.

The 109 code-smell matches and 42 IoC extractions come from bundled dependencies in the compiled dist/ directory. Every one of those files is generated output that pulls in dozens of npm libraries, and the scanner counts each library's patterns separately. That produces a large number on the page without producing evidence of misbehavior.

No finding in this bundle reads from .ssh, .aws/credentials, or any other sensitive credential path. No network call points to a domain that falls outside the package's stated purpose of talking to Zipline hosts. The package does what it says it does.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

139 detail rows
Showing 25 of 34 · highest severity first

YARA Rule Matches

10 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 11
dist/utils/security.test.jsdist/sandboxUtils.test.jsdist/mcp-integration.test.js +8 more
-
LOWpostinstall persistence mechanism 3
dist/index.jsdist/sandboxUtils.jsdist/sandboxUtils.test.js
-
LOWpostinstall file download 19
dist/remoteFolders.jsdist/index.test.jsdist/download.integration.test.js.map +16 more
-
LOWpostinstall environment access 24
dist/remoteFolders.jsdist/utils/errorMapper.jsdist/userFiles.d.ts +21 more
-
LOWpostinstall crypto operations 8
README.mddist/download.integration.test.jsdist/sandboxUtils.js +5 more
-
LOWpostinstall file manipulation 23
dist/download.integration.test.jspackage.jsondist/remoteFolders.js +20 more
-
LOWpostinstall network communication 8
dist/index.jsdist/utils/errorMapper.jsREADME.md +5 more
-
LOWpostinstall obfuscation 1
dist/utils/security.test.js
-
LOWpostinstall system command 7
README.mddist/httpClient.jsdist/utils/security.test.js +4 more
-
LOWUsingCommandLineArguments 1
dist/index.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

42 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

9
Secrets
16
Network
42
IoC Indicators

YARA Rules Matched

10 rules(105 hits)
credential env files postinstall persistence mechanism postinstall file download postinstall environment access postinstall crypto operations postinstall file manipulation postinstall network communication postinstall obfuscation postinstall system command UsingCommandLineArguments

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The single tool-poisoning finding, MCP-TOOL-TOOL-POISONING-dist/index.js-458, sits in the main entry point where MCP tools are defined. This package registers tools for uploading files to Zipline-compatible hosts, and tool definitions naturally include description fields that the scanner matches against. One finding of this type in a package that defines file-upload tools is consistent with the scanner flagging a tool description, not a hidden instruction aimed at the AI agent. No additional tool-poisoning patterns were found across the remaining 180 findings.

The nine secret findings all carry the title MCP-TRANSPORT-HARDCODED-TOKEN and every one of them lives in a .test.js file: dist/userFiles.test.js, dist/sandboxUtils.test.js, dist/index.test.js, and dist/httpClient.test.js. Test files routinely contain hardcoded tokens so that unit tests can run without external configuration. The MCP transport scanner flags these as critical, but they are test fixtures, not production credentials embedded in shipped code.

Network access is expected here. The package uploads files to Zipline hosts, and the NET-FETCH findings in dist/userFiles.js, dist/remoteFolders.js, and dist/index.js reflect that functionality. The network endpoints extracted from the bundle include zipline.diced.sh, which is a known public Zipline instance, along with etereo.one, file.xyz, and single.in which look like example hostnames or test URLs. The strings archive.zip and user1-notes.md are example filenames, not network destinations. No credential-access findings target sensitive paths like .ssh, .aws/credentials, or .kube/config. There is no harvest-then-exfiltrate pattern connecting credential reads to calls to unknown domains.

The 109 code-smell findings are all low severity and match generic Node.js patterns in bundled dist/ files. The 42 IoC findings follow the same pattern: bundled dependencies in compiled output produce multiplicative false positives that the scanner counts individually.

The strongest counterargument is that the single tool-poisoning finding in dist/index.js:458 could contain a genuine hidden directive rather than a benign tool description. Without the source code in front of us, we cannot inspect that line directly. But a single match in a package whose entire purpose is defining upload tools, with no corroborating findings of exfiltration, credential theft, or suspicious network calls, does not establish malicious intent. The weight of evidence points to a legitimate file-upload MCP server whose bundled output and test files triggered the scanner's broad matching rules.

Key Reasons

  • Single tool-poisoning finding is in tool definition code, consistent with scanner false positive on description fields
  • All 9 hardcoded-token findings are in .test.js test fixture files
  • Network calls target zipline.diced.sh, a known public Zipline instance matching the package's stated purpose
  • No credential-access findings target sensitive paths like .ssh or .aws/credentials
  • No harvest-then-exfiltrate pattern connecting any credential reads to unknown domain calls

False Positive Considerations

  • MCP-TRANSPORT-HARDCODED-TOKEN findings in .test.js files are test fixtures, not production secrets
  • MCP-TOOL-TOOL-POISONING match in tool definition code, not a hidden AI directive
  • 109 code-smell findings from bundled dist/ dependencies
  • 42 IoC extractions from compiled output with multiplicative false positives

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 78%.

MCP version history

Risk trend by version

17 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
100
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
1.12.7
Apr 18, 2026
Risk range
100 to 100
Across analyzed versions
Latest analyzed version
1.12.24
Sep 29, 2026
Selected version
critical
Version
v1.12.24
2 days ago
Risk score
100
Findings
181
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

An MCP server to upload files to a Zipline-compatible host.

Frequently Asked Questions