@spec-driven-steroids/mcp
Unknown developer
Threat Summary
Key Security Threats
YARA rule match: -postinstall_system_command
/tmp/extract-765c48d9b8cbc31854c8d8d87cccc377b0e9910d4bfb8b5600ebc985446a77a7-2817929965/dist/index.d.ts
YARA rule match: -postinstall_file_manipulation
/tmp/extract-765c48d9b8cbc31854c8d8d87cccc377b0e9910d4bfb8b5600ebc985446a77a7-2817929965/dist/index.js
YARA rule match: -postinstall_network_communication
/tmp/extract-765c48d9b8cbc31854c8d8d87cccc377b0e9910d4bfb8b5600ebc985446a77a7-2817929965/dist/index.js
YARA rule match: -postinstall_system_command
/tmp/extract-765c48d9b8cbc31854c8d8d87cccc377b0e9910d4bfb8b5600ebc985446a77a7-2817929965/dist/index.js
YARA rule match: -postinstall_network_communication
/tmp/extract-765c48d9b8cbc31854c8d8d87cccc377b0e9910d4bfb8b5600ebc985446a77a7-2817929965/LICENSE
All Findings (23)
View all 23 security findings
YARA rule match: -postinstall_system_command
YARA rule match: -postinstall_file_manipulation
YARA rule match: -postinstall_network_communication
YARA rule match: -postinstall_system_command
YARA rule match: -postinstall_network_communication
MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-519
MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-531
MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-543
MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-95
XIOC detected Domain: requirements.md
XIOC detected Domain: gmail.com
XIOC detected Domain: readme.md
XIOC detected Email: [email protected]
XIOC detected URL: https://github.com/lindoelio/spec-driven-steroids.git
XIOC detected Domain: design.md
XIOC detected Domain: tasks.md
XIOC detected Domain: index.d.ts.map
XIOC detected Domain: skill.md
XIOC detected Domain: docs.design
XIOC detected Domain: index.js.map
XIOC detected Domain: github.com
HASH-12b2f95d90a1a793
HASH-18d19bc33c4b4fc7
Recommended Action
This extension has significant security concerns that warrant careful review. Consider uninstalling or finding a safer alternative. If you must use it, limit the permissions and monitor for suspicious activity.