MCP Registry

@kya-os/mcp-i

by h0bb5
d6805352-be30-5987-99d6-e18b407d9136 | v1.13.2
82/ 100
HIGH risk
No change since v1.13.1
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (82/100) still counts them.

Analysis record

Analysed
Today
Version
v1.13.2
Artifact
SHA256 D8A…5E0
Source
Findings (non-IoC)

Is @kya-os/mcp-i safe?

@kya-os/mcp-i is a TypeScript framework for building MCP servers, the layer that lets an AI agent call tools a developer defines. It declares no permissions and no fixed network endpoints, which is normal for a library that runs inside someone else's server. The network calls in the package sit in files such as dist/auth/oauth/providers/proxy-provider.js, which fetches from an OAuth provider, and dist/cache/cloudflare-kv.js, which talks to Cloudflare's key-value store. Both are features the framework advertises.

Four findings carry the label MCP-TOOL-TOOL-POISONING, including MCP-TOOL-TOOL-POISONING-dist/runtime/stdio.js-7 and the same pattern in the Express and Next.js adapters. If those were real, they would mean hidden instructions aimed at an AI agent, planted in a tool description the agent reads. What is actually at those line numbers is the code that registers tools and their descriptions for the developer using the framework. The scanner sees a description field attached to a tool and flags it, without knowing whether the text came from the framework author or was slipped in over someone else's tool.

The rest of the picture is empty in the ways that matter. No code in the package reads SSH keys, AWS credentials or Kubernetes config files. There are no malware signatures, no obfuscated files and no unknown domains. The sixteen network call sites all sit in dist/ and match features named in their file paths: an OAuth router, a Cloudflare cache, an HTTP provider, checkpoint verification and batch proof submission.

One caveat sits outside the code. The publisher is not a widely known vendor and the package has no users yet, so a future version is worth a fresh look. This build does not do anything its description fails to mention.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

29 detail rows
Showing 25 of 29 · highest severity first

Finding Categories

16
Network

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

@kya-os/mcp-i is a TypeScript MCP framework at version 1.13.1, published by h0bb5. It builds MCP servers and ships the pieces those servers need: stdio and HTTP transports, Express and Next.js adapters, OAuth proxy support, a Cloudflare KV cache backend and a delegation verifier. The package declares no permissions and no static network endpoints, which is what a library that runs inside the developer's own server looks like.

Tool poisoning is the first thing to check, and all four critical findings come from that rule: MCP-TOOL-TOOL-POISONING-dist/runtime/stdio.js-7, the same title at dist/runtime/http.js-8, dist/runtime/adapter-express.js-8 and dist/runtime/adapter-nextjs.js-8. Those four files are the transport entry points, the exact places where a framework registers tool names and description strings so a developer's tools become visible to an agent. The rule matches the shape of a tool definition, an object with a description field aimed at a model, and it cannot tell whether the string was written by the framework author or injected over someone else's tool. The flagged paths contain no hidden directives, no instruction tags, no 'do not tell the user' text and no invisible Unicode (the obfuscation category is empty). These are tool definitions, the documented false-positive pattern for SDKs.

On credentials, the package reads nothing sensitive. There are no credential-access findings at all, so no code path touches ~/.ssh, ~/.aws/credentials, ~/.kube/config or application_default_credentials.json, and there are no secret findings. Configuration env reads are the framework's business and the scanner did not flag any.

Network access is real but ordinary. The sixteen NET-FETCH hits all sit under dist/: dist/auth/oauth/providers/proxy-provider.js:54, :102 and :128, dist/auth/oauth/router.js:218, dist/cache/cloudflare-kv.js:20, dist/providers/node-providers.js:173, dist/runtime/delegation-verifier-checkpoint.js:137, :174 and :199, dist/runtime/proof-batch-queue.js:85 and :151, and dist/runtime/stdio.js:1 and :4. Read by filename, they map one-to-one onto features the package advertises: OAuth provider proxying, an OAuth router, a Cloudflare KV cache, an HTTP provider, checkpoint verification for delegation and batch proof submission. None of them is paired with a credential read, which is the combination that would signal exfiltration. The IoC list is empty, so no unknown domain is hiding in the bundle.

The strongest argument against this reading is the publisher. h0bb5 is not a known vendor, the package has no users yet, and MCP tooling gets less vetting than browser extensions, so an unfamiliar framework with this much history is worth watching. That argument concerns trust in the author, not anything in this artifact: zero malware signatures, zero obfuscation, zero credential access, zero suspicious domains. A future release could change that, and diffing 1.14.0 against this build is the cheap way to catch it.

Key Reasons

  • All four critical tool-poisoning hits are in dist/runtime transport entry points (stdio.js:7, http.js:8, adapter-express.js:8, adapter-nextjs.js:8), the places a framework registers tool definitions
  • No credential-access findings, no secret findings, and no reads of ~/.ssh, ~/.aws/credentials or ~/.kube/config anywhere in the package
  • All sixteen NET-FETCH hits sit in dist/ and match advertised features: proxy-provider.js, oauth/router.js, cloudflare-kv.js, node-providers.js, delegation-verifier-checkpoint.js, proof-batch-queue.js
  • Zero IoC, zero malware signatures, zero obfuscation findings
  • Publisher is unknown with no user base, so version history is the only remaining risk surface

False Positive Considerations

  • Tool-poisoning rule matching legitimate tool definition strings in SDK transport adapters
  • Bundled/dist output inflating general finding counts
  • Framework networking (OAuth proxy, Cloudflare KV cache) flagged as generic NET-FETCH

Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 75%.

MCP version history

Risk trend by version

11 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
82
Change since first
-2
Change from previous
No change
Versions:
First analyzed version
1.10.0
Apr 23, 2026
Risk range
74 to 84
Across analyzed versions
Latest analyzed version
1.13.2
Oct 1, 2026
Selected version
high
Version
v1.13.2
Today
Risk score
82
Findings
29
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

The TypeScript MCP framework with identity features built-in

Frequently Asked Questions