zipline-mcp
The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v1.12.24
- Artifact
- SHA256 F75…A36
- Source
- Findings (non-IoC)
Is zipline-mcp safe?
zipline-mcp is an MCP server that uploads files to Zipline-compatible hosting services. The package makes network calls through dist/index.js, dist/userFiles.js, and dist/remoteFolders.js to reach hosts like zipline.diced.sh, which is a real public Zipline instance. It declares no special permissions and no host permissions in its manifest.
The scanner flagged one tool-poisoning match at dist/index.js:458. That line lives in the section of code where the package registers its upload tools, and tool descriptions are exactly what the scanner looks for when it hunts hidden AI instructions. Nine hardcoded-token findings all sit inside .test.js files where fake credentials belong. Neither category of finding reaches into production code.
The 109 code-smell matches and 42 IoC extractions come from bundled dependencies in the compiled dist/ directory. Every one of those files is generated output that pulls in dozens of npm libraries, and the scanner counts each library's patterns separately. That produces a large number on the page without producing evidence of misbehavior.
No finding in this bundle reads from .ssh, .aws/credentials, or any other sensitive credential path. No network call points to a domain that falls outside the package's stated purpose of talking to Zipline hosts. The package does what it says it does.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
10 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 11 | dist/download.test.jsdist/utils/security.jsdist/sandboxUtils.js +8 more | - |
| LOW | postinstall persistence mechanism | 3 | dist/sandboxUtils.test.jsdist/index.jsdist/sandboxUtils.js | - |
| LOW | postinstall file download | 19 | dist/remoteFolders.jsdist/index.test.jsdist/download.integration.test.js.map +16 more | - |
| LOW | UsingCommandLineArguments | 1 | dist/index.js | - |
| LOW | postinstall environment access | 24 | dist/sandboxUtils.test.jsdist/utils/errorMapper.jsdist/index.test.js +21 more | - |
| LOW | postinstall crypto operations | 8 | README.mddist/index.test.jsdist/sandboxUtils.test.js +5 more | - |
| LOW | postinstall file manipulation | 23 | dist/remoteFolders.d.tsdist/userFiles.test.jsdist/httpClient.test.js +20 more | - |
| LOW | postinstall network communication | 8 | dist/download.test.jsdist/utils/errorMapper.jsREADME.md +5 more | - |
| LOW | postinstall obfuscation | 1 | dist/utils/security.test.js | - |
| LOW | postinstall system command | 7 | README.mddist/httpClient.jsdist/utils/security.test.js +4 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
10 rules(105 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The single tool-poisoning finding, MCP-TOOL-TOOL-POISONING-dist/index.js-458, sits in the main entry point where MCP tools are defined. This package registers tools for uploading files to Zipline-compatible hosts, and tool definitions naturally include description fields that the scanner matches against. One finding of this type in a package that defines file-upload tools is consistent with the scanner flagging a tool description, not a hidden instruction aimed at the AI agent. No additional tool-poisoning patterns were found across the remaining 180 findings.
The nine secret findings all carry the title MCP-TRANSPORT-HARDCODED-TOKEN and every one of them lives in a .test.js file: dist/userFiles.test.js, dist/sandboxUtils.test.js, dist/index.test.js, and dist/httpClient.test.js. Test files routinely contain hardcoded tokens so that unit tests can run without external configuration. The MCP transport scanner flags these as critical, but they are test fixtures, not production credentials embedded in shipped code.
Network access is expected here. The package uploads files to Zipline hosts, and the NET-FETCH findings in dist/userFiles.js, dist/remoteFolders.js, and dist/index.js reflect that functionality. The network endpoints extracted from the bundle include zipline.diced.sh, which is a known public Zipline instance, along with etereo.one, file.xyz, and single.in which look like example hostnames or test URLs. The strings archive.zip and user1-notes.md are example filenames, not network destinations. No credential-access findings target sensitive paths like .ssh, .aws/credentials, or .kube/config. There is no harvest-then-exfiltrate pattern connecting credential reads to calls to unknown domains.
The 109 code-smell findings are all low severity and match generic Node.js patterns in bundled dist/ files. The 42 IoC findings follow the same pattern: bundled dependencies in compiled output produce multiplicative false positives that the scanner counts individually.
The strongest counterargument is that the single tool-poisoning finding in dist/index.js:458 could contain a genuine hidden directive rather than a benign tool description. Without the source code in front of us, we cannot inspect that line directly. But a single match in a package whose entire purpose is defining upload tools, with no corroborating findings of exfiltration, credential theft, or suspicious network calls, does not establish malicious intent. The weight of evidence points to a legitimate file-upload MCP server whose bundled output and test files triggered the scanner's broad matching rules.
Key Reasons
- Single tool-poisoning finding is in tool definition code, consistent with scanner false positive on description fields
- All 9 hardcoded-token findings are in .test.js test fixture files
- Network calls target zipline.diced.sh, a known public Zipline instance matching the package's stated purpose
- No credential-access findings target sensitive paths like .ssh or .aws/credentials
- No harvest-then-exfiltrate pattern connecting any credential reads to unknown domain calls
False Positive Considerations
- MCP-TRANSPORT-HARDCODED-TOKEN findings in .test.js files are test fixtures, not production secrets
- MCP-TOOL-TOOL-POISONING match in tool definition code, not a hidden AI directive
- 109 code-smell findings from bundled dist/ dependencies
- 42 IoC extractions from compiled output with multiplicative false positives
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 78%.
MCP version history
Risk trend by version
17 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace