MCP Registry

@azure/mcp-linux-x64

e4d973db-c2ee-5202-b155-b736bb7d2c5d | v3.0.0-beta.49
46/ 100
MEDIUM risk
No change since v3.0.0-beta.48
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (46/100) still counts them.

Analysis record

Analysed
Today
Version
v3.0.0-beta.49
Artifact
SHA256 EFF…CB5
Source
Findings (non-IoC)

Is @azure/mcp-linux-x64 safe?

@azure/mcp-linux-x64 carries the Linux x64 build of Microsoft's Azure MCP Server, the component an AI assistant uses to reach Azure subscriptions. The package asks for zero permissions and zero host permissions. Its extracted address list holds microsoft.identity.client.platforms.net, a hostname that ships inside Microsoft's identity libraries, alongside documentation filenames like 5-verify.md and shared-object names like 6libmicrosoft.cognitiveservices.speech.extension.kws.so. Those strings live inside the compiled binaries.

Nearly every entry the scanner produced carries a title like XIOC-SHA256-9542D903F24247CAD996975AEACEF3D262E72CB2060F229E2F61D3F2A39288AB, and 11,025 of them came from hashing files under extracted_from_files. A hash of that kind would matter if the file behind it matched a known malware sample, and the malware-signature category holds zero matches. No finding in this package shows code reading .ssh, .aws/credentials or .kube/config, and none shows an HTTP call leaving the machine. The remaining 209 low-severity items are generic code-smell rules that fire on any large JavaScript or native bundle.

Bulk hashing of bundled files and string extraction from compiled binaries account for the whole finding set. Microsoft's 1ES group publishes this package for Azure users who install it on purpose.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

209 detail rows

YARA Rule Matches

16 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall network communication 53
dist/Instrumentation/Resources/concepts/dotnet/aspnet-classic-appinsights.mddist/azmcpdist/Instrumentation/Resources/concepts/nodejs/opentelemetry-pipeline.md +50 more
-
LOWcredential postgres credentials 1
dist/azmcp
-
LOWpostinstall crypto operations 5
NOTICE.txtREADME.mddist/Instrumentation/Resources/api-reference/dotnet/ActivityProcessors.md +2 more
-
LOWpostinstall file manipulation 15
dist/azmcpdist/Instrumentation/Resources/api-reference/dotnet/ApplicationInsightsWeb.mddist/Instrumentation/Resources/migration/dotnet/ilogger-migration.md +12 more
-
LOWpostinstall environment access 1
NOTICE.txt
-
LOWpostinstall registry modification 3
dist/azmcpNOTICE.txtREADME.md
-
LOWpostinstall obfuscation 4
dist/azmcpdist/Instrumentation/Resources/api-reference/dotnet/WithLogging.mdNOTICE.txt +1 more
-
LOWpostinstall system command 50
dist/Instrumentation/Resources/examples/dotnet/workerservice-setup.mddist/azmcpdist/Instrumentation/Resources/api-reference/dotnet/EntityFrameworkInstrumentation.md +47 more
-
LOWDebuggerStatementsShouldNotBeUsed 1
dist/azmcp
-
LOWcredential ssh keys 1
dist/azmcp
-
LOWUsingCommandLineArguments 1
index.js
-
LOWcredential env files 30
dist/azmcpdist/Instrumentation/Resources/examples/nodejs/nestjs-setup.mddist/Instrumentation/Resources/examples/nodejs/winston-setup.md +27 more
-
LOWpostinstall persistence mechanism 22
dist/Instrumentation/Resources/examples/python/django-setup.mddist/Instrumentation/Resources/examples/nodejs/postgres-setup.mddist/azmcp +19 more
-
LOWpostinstall file download 18
dist/azmcpdist/Instrumentation/Resources/examples/nodejs/console-setup.mddist/Azure.Mcp.Tools.AzureMigrate.xml +15 more
-
LOWpostinstall process injection 1
dist/azmcp
-
LOWNoUseWeakRandom 3
dist/azmcpdist/Instrumentation/Resources/examples/nodejs/bunyan-setup.mddist/Instrumentation/Resources/examples/nodejs/console-setup.md
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

11,018 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

11,018
IoC Indicators

YARA Rules Matched

16 rules(209 hits)
postinstall network communication credential postgres credentials postinstall crypto operations postinstall file manipulation postinstall environment access postinstall registry modification postinstall obfuscation postinstall system command DebuggerStatementsShouldNotBeUsed credential ssh keys UsingCommandLineArguments credential env files postinstall persistence mechanism postinstall file download postinstall process injection NoUseWeakRandom

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

@azure/mcp-linux-x64 carries the Linux x64 payload of Microsoft's Azure MCP Server, published under the microsoft1es developer name at version 3.0.0-beta.48. The package declares no permissions and no host permissions, produces no network findings, and its 11,234 entries come almost entirely from static extraction run across bundled files.

Tool poisoning. The tool-poisoning category holds zero findings. Nothing in this package contains directives aimed at an AI agent, nothing tells an assistant to hide behaviour from the user, and nothing asks for a command to run before a reply. That fits what this artifact is: a per-platform binary distribution. Tool definitions and descriptions for Azure live in the main server package, which this one supplies a runtime for.

Credentials and network. Zero secret findings and zero credential-access findings. Nothing here reads .ssh, .aws/credentials, .kube/config or application_default_credentials.json, so there is no harvest step. There is also no send step, because the network category is empty. The endpoint list is extraction noise rather than destinations: entries such as 5-verify.md and 6-generate-iac.md are markdown filenames from the repository docs, 6libmicrosoft.cognitiveservices.speech.extension.kws.so is a shared-object filename, and 0asp.net, 2qv.tk and 1n.gr are fragments of longer strings inside compiled libraries. The one hostname that maps to a shipped Microsoft product, microsoft.identity.client.platforms.net, belongs to Microsoft's identity client libraries. Exfiltration needs a credential read next to a call to an unknown host, and neither side of that pair exists here.

The IoC set is 11,025 medium-severity SHA256 hashes plus that single domain, every one of them tagged extracted_from_files. A hash finding means the scanner hashed a file it unpacked. It becomes a problem only when the file behind it matches a known sample, and the malware-signature category reports zero matches across the entire package. The remaining 209 low-severity entries are code-smell rules that fire on any large JavaScript or native bundle.

Strongest counterargument. Platform-specific native packages skip the source review that a plain npm package invites, and 3.0.0-beta.48 is a prerelease on a fast version cadence, which is exactly the shape a rug-pull would take. That argument would matter if any signal pointed at behaviour. Tool poisoning, network activity, credential access and malware signatures all read zero, and a malicious later build would move at least one of those. Microsoft's 1ES group publishing @azure/mcp-linux-x64 under the @azure scope also rules out typosquatting and name squatting.

Key Reasons

  • Zero tool-poisoning findings, which fits a platform-specific binary with no tool descriptions of its own
  • Zero secret and zero credential-access findings: nothing references .ssh, .aws/credentials or .kube/config
  • Zero network findings and zero malware-signature matches, so no harvest-and-send architecture exists here
  • The endpoint list is extraction noise: 5-verify.md and 6-generate-iac.md are doc filenames, 6libmicrosoft.cognitiveservices.speech.extension.kws.so is a shared-object name
  • Published under the microsoft1es developer name inside the @azure scope at version 3.0.0-beta.48, with no name-squatting signal

False Positive Considerations

  • XIOC hashing of every bundled native binary and shared library under extracted_from_files
  • Domain-shaped fragments parsed out of compiled library strings, markdown filenames and .so names
  • YARA code-smell rules firing on bundled JavaScript in a large dist payload
  • No manifest, network, credential or tool-poisoning findings to corroborate any of it

Reviewed 2026-10-01; recommended action: no action; model confidence 84%.

MCP version history

Risk trend by version

8 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
46
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
3.0.0-beta.42
Sep 9, 2026
Risk range
46 to 46
Across analyzed versions
Latest analyzed version
3.0.0-beta.49
Oct 2, 2026
Selected version
medium
Version
v3.0.0-beta.49
Today
Risk score
46
Findings
11227
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Azure MCP Server - Model Context Protocol implementation for Azure, for linux on x64

Frequently Asked Questions