MCP Registry

@microsoft/powerbi-modeling-mcp-linux-x64

ebf96781-0eb7-5a97-920d-885a3b79c486 | v1.0.0
44/ 100
MEDIUM risk
+1 since v0.5.0-beta.13
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 days ago
Version
v1.0.0
Artifact
SHA256 5D7…C50
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

37 detail rows

YARA Rule Matches

14 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 2
index.jsdist/powerbi-modeling-mcp
-
LOWpostinstall persistence mechanism 2
CHANGELOG.mddist/powerbi-modeling-mcp
-
LOWpostinstall crypto operations 2
NOTICE.txtdist/powerbi-modeling-mcp
-
LOWpostinstall system command 7
dist/powerbi-modeling-mcpdist/Resources/dax_udf_instructions_and_examples.mdindex.js +4 more
-
LOWpostinstall file manipulation 5
NOTICE.txtCHANGELOG.mddist/Resources/tools/tool-metadata.yaml +2 more
-
LOWpostinstall environment access 2
dist/Resources/tools/tool-metadata.yamlNOTICE.txt
-
LOWpostinstall registry modification 1
dist/powerbi-modeling-mcp
-
LOWpostinstall obfuscation 5
dist/Resources/dax_udf_instructions_and_examples.mdNOTICE.txtCHANGELOG.md +2 more
-
LOWpostinstall network communication 5
LICENSENOTICE.txtCHANGELOG.md +2 more
-
LOWpostinstall file download 2
dist/Resources/tools/tool-metadata.yamldist/powerbi-modeling-mcp
-
LOWpostinstall process injection 1
dist/powerbi-modeling-mcp
-
LOWNoUseWeakRandom 1
dist/powerbi-modeling-mcp
-
LOWDebuggerStatementsShouldNotBeUsed 1
dist/powerbi-modeling-mcp
-
LOWUsingCommandLineArguments 1
index.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

513 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

513
IoC Indicators

YARA Rules Matched

14 rules(37 hits)
credential env files postinstall persistence mechanism postinstall crypto operations postinstall system command postinstall file manipulation postinstall environment access postinstall registry modification postinstall obfuscation postinstall network communication postinstall file download postinstall process injection NoUseWeakRandom DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments

MCP Server Analysis

MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.

AI Security Report

AI Security Review

Evidence context: threat category supply chain; evidence quality moderate.

Tool Poisoning Analysis: No tool-poisoning findings were detected (0 findings in the tool-poisoning category). This package does not contain hidden AI manipulation directives in tool descriptions.

Credential/Network Access: No credential-access findings, network findings, or secret findings were detected. The evidence shows 0 findings for credential reads, network calls, or secret extraction. This is unusual for a package containing 649 domain IOCs—if these domains were actively used for C2 communication, network findings would be expected.

IOC Findings Analysis: The 649 IOC findings are all domain strings (XIOC-DOMAIN findings) including u.dk, ky.su, х.bt (Cyrillic character), cԣ.gl (Armenian character), yy.mt, zb.td, o.tz, 0.ma, dq.bi, f.bi, f.tz, s.vi. These domains exhibit classic DGA/C2 characteristics: short random strings, mixed scripts, and diverse TLDs. However, all findings show file_path as extracted_from_files without specific code locations, making it impossible to determine if these are actively called or merely embedded in bundled dependencies.

Developer Name Red Flag: The developer name is microsoft1es, not Microsoft. This is inconsistent with legitimate Microsoft publishing. While the package uses the @microsoft/ npm scope (which requires Microsoft ownership), the mismatch between scope and developer name is suspicious and warrants verification of whether Microsoft actually published this package.

Strongest Counterargument: The absence of network findings, credential-access findings, and code-smell findings suggests these domains may be embedded in bundled dependencies rather than actively used for malicious purposes. Pre-built binaries (indicated by -linux-x64 suffix) often contain numerous embedded strings from bundled libraries that trigger IOC extractors.

Why Counterargument Doesn't Resolve Concern: The combination of suspicious developer name (microsoft1es vs expected Microsoft) and 649 DGA-pattern domains is too concerning to dismiss. Manual binary analysis is required to determine if these domains are actively called or merely embedded.

Key Reasons

  • Developer name 'microsoft1es' does not match expected Microsoft publishing patterns
  • 649 domain IOCs with DGA/C2 characteristics (short random strings, mixed scripts)
  • No network or credential findings to confirm active domain usage
  • Pre-built binary format limits static analysis visibility
  • No tool-poisoning or malware-signature findings detected

False Positive Considerations

  • Bundled dependencies in pre-built binary may contain embedded domain strings
  • IOC extractor may flag domain strings without confirming active network usage
  • Pre-built binaries often contain numerous embedded strings from libraries

Reviewed 2026-04-27; recommended action: runtime analysis; model confidence 72%.

MCP version history

Risk trend by version

11 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
44
Change since first
+3
Change from previous
+1
Versions:
First analyzed version
0.5.0-beta.4
Apr 23, 2026
Risk range
34 to 44
Across analyzed versions
Latest analyzed version
1.0.0
Sep 25, 2026
Selected version
medium
Version
v1.0.0
6 days ago
Risk score
44
Findings
550
Change vs previous
+1

Pick any point on the chart to explore that version's code below.

About This Extension

Power BI Authoring MCP Server - Node.js client packaging to author Power BI semantic models in Power BI Desktop, Microsoft Fabric workspaces, and local PBIP and TMDL files., for linux on x64

Frequently Asked Questions