@azure/mcp-linux-x64
The AI review rates the findings as likely false positive, but the risk score (46/100) still counts them.
Analysis record
- Analysed
- Today
- Version
- v3.0.0-beta.49
- Artifact
- SHA256 EFF…CB5
- Source
- Findings (non-IoC)
Is @azure/mcp-linux-x64 safe?
@azure/mcp-linux-x64 carries the Linux x64 build of Microsoft's Azure MCP Server, the component an AI assistant uses to reach Azure subscriptions. The package asks for zero permissions and zero host permissions. Its extracted address list holds microsoft.identity.client.platforms.net, a hostname that ships inside Microsoft's identity libraries, alongside documentation filenames like 5-verify.md and shared-object names like 6libmicrosoft.cognitiveservices.speech.extension.kws.so. Those strings live inside the compiled binaries.
Nearly every entry the scanner produced carries a title like XIOC-SHA256-9542D903F24247CAD996975AEACEF3D262E72CB2060F229E2F61D3F2A39288AB, and 11,025 of them came from hashing files under extracted_from_files. A hash of that kind would matter if the file behind it matched a known malware sample, and the malware-signature category holds zero matches. No finding in this package shows code reading .ssh, .aws/credentials or .kube/config, and none shows an HTTP call leaving the machine. The remaining 209 low-severity items are generic code-smell rules that fire on any large JavaScript or native bundle.
Bulk hashing of bundled files and string extraction from compiled binaries account for the whole finding set. Microsoft's 1ES group publishes this package for Azure users who install it on purpose.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
16 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall network communication | 53 | dist/Instrumentation/Resources/concepts/dotnet/aspnet-classic-appinsights.mddist/azmcpdist/Instrumentation/Resources/concepts/nodejs/opentelemetry-pipeline.md +50 more | - |
| LOW | credential postgres credentials | 1 | dist/azmcp | - |
| LOW | postinstall crypto operations | 5 | NOTICE.txtREADME.mddist/Instrumentation/Resources/api-reference/dotnet/ActivityProcessors.md +2 more | - |
| LOW | postinstall file manipulation | 15 | dist/azmcpdist/Instrumentation/Resources/api-reference/dotnet/ApplicationInsightsWeb.mddist/Instrumentation/Resources/migration/dotnet/ilogger-migration.md +12 more | - |
| LOW | postinstall environment access | 1 | NOTICE.txt | - |
| LOW | postinstall registry modification | 3 | dist/azmcpNOTICE.txtREADME.md | - |
| LOW | postinstall obfuscation | 4 | dist/azmcpdist/Instrumentation/Resources/api-reference/dotnet/WithLogging.mdNOTICE.txt +1 more | - |
| LOW | postinstall system command | 50 | dist/Instrumentation/Resources/examples/dotnet/workerservice-setup.mddist/azmcpdist/Instrumentation/Resources/api-reference/dotnet/EntityFrameworkInstrumentation.md +47 more | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 1 | dist/azmcp | - |
| LOW | credential ssh keys | 1 | dist/azmcp | - |
| LOW | UsingCommandLineArguments | 1 | index.js | - |
| LOW | credential env files | 30 | dist/azmcpdist/Instrumentation/Resources/examples/nodejs/nestjs-setup.mddist/Instrumentation/Resources/examples/nodejs/winston-setup.md +27 more | - |
| LOW | postinstall persistence mechanism | 22 | dist/Instrumentation/Resources/examples/python/django-setup.mddist/Instrumentation/Resources/examples/nodejs/postgres-setup.mddist/azmcp +19 more | - |
| LOW | postinstall file download | 18 | dist/azmcpdist/Instrumentation/Resources/examples/nodejs/console-setup.mddist/Azure.Mcp.Tools.AzureMigrate.xml +15 more | - |
| LOW | postinstall process injection | 1 | dist/azmcp | - |
| LOW | NoUseWeakRandom | 3 | dist/azmcpdist/Instrumentation/Resources/examples/nodejs/bunyan-setup.mddist/Instrumentation/Resources/examples/nodejs/console-setup.md | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
16 rules(209 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
@azure/mcp-linux-x64 carries the Linux x64 payload of Microsoft's Azure MCP Server, published under the microsoft1es developer name at version 3.0.0-beta.48. The package declares no permissions and no host permissions, produces no network findings, and its 11,234 entries come almost entirely from static extraction run across bundled files.
Tool poisoning. The tool-poisoning category holds zero findings. Nothing in this package contains directives aimed at an AI agent, nothing tells an assistant to hide behaviour from the user, and nothing asks for a command to run before a reply. That fits what this artifact is: a per-platform binary distribution. Tool definitions and descriptions for Azure live in the main server package, which this one supplies a runtime for.
Credentials and network. Zero secret findings and zero credential-access findings. Nothing here reads .ssh, .aws/credentials, .kube/config or application_default_credentials.json, so there is no harvest step. There is also no send step, because the network category is empty. The endpoint list is extraction noise rather than destinations: entries such as 5-verify.md and 6-generate-iac.md are markdown filenames from the repository docs, 6libmicrosoft.cognitiveservices.speech.extension.kws.so is a shared-object filename, and 0asp.net, 2qv.tk and 1n.gr are fragments of longer strings inside compiled libraries. The one hostname that maps to a shipped Microsoft product, microsoft.identity.client.platforms.net, belongs to Microsoft's identity client libraries. Exfiltration needs a credential read next to a call to an unknown host, and neither side of that pair exists here.
The IoC set is 11,025 medium-severity SHA256 hashes plus that single domain, every one of them tagged extracted_from_files. A hash finding means the scanner hashed a file it unpacked. It becomes a problem only when the file behind it matches a known sample, and the malware-signature category reports zero matches across the entire package. The remaining 209 low-severity entries are code-smell rules that fire on any large JavaScript or native bundle.
Strongest counterargument. Platform-specific native packages skip the source review that a plain npm package invites, and 3.0.0-beta.48 is a prerelease on a fast version cadence, which is exactly the shape a rug-pull would take. That argument would matter if any signal pointed at behaviour. Tool poisoning, network activity, credential access and malware signatures all read zero, and a malicious later build would move at least one of those. Microsoft's 1ES group publishing @azure/mcp-linux-x64 under the @azure scope also rules out typosquatting and name squatting.
Key Reasons
- Zero tool-poisoning findings, which fits a platform-specific binary with no tool descriptions of its own
- Zero secret and zero credential-access findings: nothing references .ssh, .aws/credentials or .kube/config
- Zero network findings and zero malware-signature matches, so no harvest-and-send architecture exists here
- The endpoint list is extraction noise: 5-verify.md and 6-generate-iac.md are doc filenames, 6libmicrosoft.cognitiveservices.speech.extension.kws.so is a shared-object name
- Published under the microsoft1es developer name inside the @azure scope at version 3.0.0-beta.48, with no name-squatting signal
False Positive Considerations
- XIOC hashing of every bundled native binary and shared library under extracted_from_files
- Domain-shaped fragments parsed out of compiled library strings, markdown filenames and .so names
- YARA code-smell rules firing on bundled JavaScript in a large dist payload
- No manifest, network, credential or tool-poisoning findings to corroborate any of it
Reviewed 2026-10-01; recommended action: no action; model confidence 84%.
MCP version history
Risk trend by version
8 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace