HIGH RISK NaN/100

@dezkareid/ai-team

Unknown developer

Threat Summary

Risk Level
Critical Issues
High Issues
Total Findings

Key Security Threats

HIGH Malware Signature

YARA rule match: -postinstall_file_manipulation

/tmp/extract-b3d5c3e3d6ec073eb41ba2031a4eae3170b02539c8cf0e91d8e730e477539ce5-3680295793/AGENTS.md

HIGH Malware Signature

YARA rule match: -postinstall_registry_modification

/tmp/extract-b3d5c3e3d6ec073eb41ba2031a4eae3170b02539c8cf0e91d8e730e477539ce5-3680295793/AGENTS.md

HIGH Malware Signature

YARA rule match: -postinstall_system_command

/tmp/extract-b3d5c3e3d6ec073eb41ba2031a4eae3170b02539c8cf0e91d8e730e477539ce5-3680295793/AGENTS.md

HIGH credential-access

MCP tool poisoning risk: CREDENTIAL-ACCESS-dist/mcp-server/index.js-20920

dist/mcp-server/index.js:20920

HIGH Malware Signature

YARA rule match: -postinstall_system_command

/tmp/extract-b3d5c3e3d6ec073eb41ba2031a4eae3170b02539c8cf0e91d8e730e477539ce5-3680295793/README.md

All Findings (265)

View all 265 security findings
Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_registry_modification

Malware Signature

YARA rule match: -postinstall_system_command

credential-access

MCP tool poisoning risk: CREDENTIAL-ACCESS-dist/mcp-server/index.js-20920

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_obfuscation

Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_file_download

Malware Signature

YARA rule match: -postinstall_registry_modification

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -postinstall_persistence_mechanism

Malware Signature

YARA rule match: -postinstall_crypto_operations

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -postinstall_system_command

filesystem-access

MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/mcp-server/index.js-6465

Malware Signature

YARA rule match: -postinstall_system_command

Indicator of Compromise

XIOC detected Domain: wscomponent.secure

Indicator of Compromise

XIOC detected Domain: inst.constructor.name

Indicator of Compromise

XIOC detected URL: https://github.com/dezkareid/ai-team#readme

Indicator of Compromise

XIOC detected SHA1 Hash: 47339c03c143bb4ec01a26e721a1b8fe66634ebe

Indicator of Compromise

XIOC detected URL: https://github.com/mafintosh/is-my-json-valid/blob/master/formats.js

Indicator of Compromise

XIOC detected URL: http://stackoverflow.com/questions/201323/using-a-regular-expression-to-validate-an-email-address#answer-8829363

Indicator of Compromise

XIOC detected URL: https://tools.ietf.org/html/rfc3339#appendix-C

Indicator of Compromise

XIOC detected URL: http://jmrware.com/articles/2009/uri_regexp/URI_regex.html

Indicator of Compromise

XIOC detected URL: https://example.com/auth'

Indicator of Compromise

XIOC detected URL: https://github.com/modelcontextprotocol/modelcontextprotocol/issues/986)

Indicator of Compromise

XIOC detected URL: https://github.com/dezkareid/ai-team.git

Indicator of Compromise

XIOC detected URL: https://www.safaribooksonline.com/library/view/regular-expressions-cookbook/9780596802837/ch07s16.html

Indicator of Compromise

XIOC detected URL: http://tools.ietf.org/html/rfc4122

Indicator of Compromise

XIOC detected URL: https://tools.ietf.org/html/rfc6901

Indicator of Compromise

XIOC detected URL: https://tools.ietf.org/html/rfc3986#appendix-A

Indicator of Compromise

XIOC detected URL: http://tools.ietf.org/html/draft-luff-relative-json-pointer-00

Indicator of Compromise

XIOC detected URL: https://spec.openapis.org/oas/v3.0.0#data-types

Indicator of Compromise

XIOC detected URL: https://github.com/miguelmota/is-base64

Indicator of Compromise

XIOC detected URL: http://json-schema.org/draft-07/schema

Indicator of Compromise

XIOC detected URL: http://json-schema.org/schema

Indicator of Compromise

XIOC detected URL: http://tools.ietf.org/html/rfc3339#section-5.6

Indicator of Compromise

XIOC detected URL: https://tools.ietf.org/html/rfc3339#appendix-A

Indicator of Compromise

XIOC detected URL: https://tools.ietf.org/html/rfc6570

Indicator of Compromise

XIOC detected URL: https://gist.github.com/dperini/729294

Indicator of Compromise

XIOC detected URL: https://mathiasbynens.be/demo/url-regex

Indicator of Compromise

XIOC detected URL: https://json-schema.org/draft/2019-09/schema#

Indicator of Compromise

XIOC detected URL: https://raw.githubusercontent.com/ajv-validator/ajv/master/lib/refs/data.json#

Indicator of Compromise

XIOC detected URL: https://datatracker.ietf.org/doc/html/rfc3986#section-5.2.4

Indicator of Compromise

XIOC detected URL: https://raw.githubusercontent.com/ajv-validator/ajv/master/lib/refs/data.json#

Indicator of Compromise

XIOC detected URL: https://mathiasbynens.be/notes/javascript-encoding

Indicator of Compromise

XIOC detected URL: https://github.com/bestiejs/punycode.js

Indicator of Compromise

XIOC detected URL: https://github.com/ajv-validator/ajv/issues/889

Indicator of Compromise

XIOC detected URL: https://json-schema.org/draft/2020-12/schema

Indicator of Compromise

XIOC detected URL: http://json-schema.org/draft-07/schema#

Indicator of Compromise

XIOC detected URL: http://json-schema.org/draft-04/schema#

Indicator of Compromise

XIOC detected URL: https://github.com/modelcontextprotocol/modelcontextprotocol/blob/47339c03c143bb4ec01a26e721a1b8fe66634ebe/docs/specification/draft/basic/index.mdx#general-fields)

Indicator of Compromise

XIOC detected URL: https://github.com/colinhacks/zod/blob/master/src/types.ts.

Indicator of Compromise

XIOC detected URL: https://github.com/colinhacks/zod/issues/2433

Indicator of Compromise

XIOC detected URL: https://github.com/colinhacks/zod/commit/9340fd51e48576a75adc919bff65dbc4a5d4c99b

Indicator of Compromise

XIOC detected URL: https://thekevinscott.com/emojis-in-javascript/#writing-a-regular-expression

Indicator of Compromise

XIOC detected URL: https://stackoverflow.com/questions/7860392/determine-if-string-is-in-base64-using-javascript

Indicator of Compromise

XIOC detected URL: https://base64.guru/standards/base64url

Indicator of Compromise

XIOC detected URL: https://stackoverflow.com/a/3143231

Indicator of Compromise

XIOC detected URL: https://stackoverflow.com/questions/3966484/why-does-modulus-operator-return-fractional-number-in-javascript/31711034#31711034

Indicator of Compromise

XIOC detected URL: https://blog.stevenlevithan.com/archives/validate-phone-number#r4-3

Indicator of Compromise

XIOC detected URL: http://[$

Indicator of Compromise

XIOC detected Domain: registeredresource.name

Indicator of Compromise

XIOC detected Domain: stdin.off

Indicator of Compromise

XIOC detected Domain: index.js.map

Indicator of Compromise

XIOC detected Domain: gmail.com

Indicator of Compromise

XIOC detected Email: [email protected]

Indicator of Compromise

XIOC detected URL: https://github.com/dezkareid/ai-team

Indicator of Compromise

XIOC detected URL: https://stackoverflow.com/a/46181/1550155

Indicator of Compromise

XIOC detected Domain: capabilities.tools

Indicator of Compromise

XIOC detected Domain: invalidchars.map

Indicator of Compromise

XIOC detected Domain: request.params.name

Indicator of Compromise

XIOC detected Domain: ref.name

Indicator of Compromise

XIOC detected Domain: request.params.argument.name

Indicator of Compromise

XIOC detected Domain: skill.md

Indicator of Compromise

XIOC detected Domain: params.tools

Indicator of Compromise

XIOC detected Domain: c.id

Indicator of Compromise

XIOC detected SHA1 Hash: 9340fd51e48576a75adc919bff65dbc4a5d4c99b

Indicator of Compromise

XIOC detected Domain: requests.tools

Indicator of Compromise

XIOC detected Domain: logginglevelschema.options.map

Indicator of Compromise

XIOC detected Domain: validatedrequest.data

Indicator of Compromise

XIOC detected Domain: taskvalidationresult.data

Indicator of Compromise

XIOC detected Domain: validationresult.data

Indicator of Compromise

XIOC detected Domain: it.opts.next

Indicator of Compromise

XIOC detected Domain: parentschema.properties

Indicator of Compromise

XIOC detected Domain: props.map

Indicator of Compromise

XIOC detected Domain: patprops.map

Indicator of Compromise

XIOC detected Domain: opts.next

Indicator of Compromise

XIOC detected Domain: sch.properties

Indicator of Compromise

XIOC detected Domain: fmtdef.compare

Indicator of Compromise

XIOC detected Domain: ops.gt

Indicator of Compromise

XIOC detected Domain: ops.lt

Indicator of Compromise

XIOC detected Domain: cxt.fail

Indicator of Compromise

XIOC detected Domain: 1.operators.gt

Indicator of Compromise

XIOC detected Domain: 1.operators.lt

Indicator of Compromise

XIOC detected Domain: cxt.parentschema.properties

Indicator of Compromise

XIOC detected Domain: schema.map

Indicator of Compromise

XIOC detected Domain: addrule.call

Indicator of Compromise

XIOC detected Domain: keywordmetaschema.call

Indicator of Compromise

XIOC detected Domain: 1.getschemarefs.call

Indicator of Compromise

XIOC detected Domain: 1.compileschema.call

Indicator of Compromise

XIOC detected Domain: definition.post

Indicator of Compromise

XIOC detected Domain: addbeforerule.call

Indicator of Compromise

XIOC detected Domain: 1.resolveref.call

Indicator of Compromise

XIOC detected Domain: compileasync.call

Indicator of Compromise

XIOC detected Domain: checkloaded.call

Indicator of Compromise

XIOC detected Domain: loadmissingschema.call

Indicator of Compromise

XIOC detected Domain: loadschema.call

Indicator of Compromise

XIOC detected Domain: getschenv.call

Indicator of Compromise

XIOC detected Domain: 1.resolveschema.call

Indicator of Compromise

XIOC detected Domain: checkkeyword.call

Indicator of Compromise

XIOC detected Domain: getmetaschemaoptions.call

Indicator of Compromise

XIOC detected Domain: addinitialformats.call

Indicator of Compromise

XIOC detected Domain: addinitialkeywords.call

Indicator of Compromise

XIOC detected Domain: addinitialschemas.call

Indicator of Compromise

XIOC detected Domain: datarefschema.id

Indicator of Compromise

XIOC detected Domain: runcompileasync.call

Indicator of Compromise

XIOC detected Domain: loadmetaschema.call

Indicator of Compromise

XIOC detected Domain: relative.host

Indicator of Compromise

XIOC detected Domain: base.host

Indicator of Compromise

XIOC detected Domain: cmpts.host

Indicator of Compromise

XIOC detected Domain: cmpts.secure

Indicator of Compromise

XIOC detected Domain: parsed.host

Indicator of Compromise

XIOC detected Domain: o.int

Indicator of Compromise

XIOC detected Domain: checkoptions.call

Indicator of Compromise

XIOC detected Domain: resolveschema.call

Indicator of Compromise

XIOC detected Domain: getjsonpointer.call

Indicator of Compromise

XIOC detected Domain: output.zone

Indicator of Compromise

XIOC detected Domain: ipv6.zone

Indicator of Compromise

XIOC detected Domain: component.host

Indicator of Compromise

XIOC detected Domain: target.host

Indicator of Compromise

XIOC detected Domain: resource.name

Indicator of Compromise

XIOC detected Domain: rules.post

Indicator of Compromise

XIOC detected Domain: updates.name

Indicator of Compromise

XIOC detected Domain: this.fail

Indicator of Compromise

XIOC detected Domain: getcompilingschema.call

Indicator of Compromise

XIOC detected Domain: resolve.call

Indicator of Compromise

XIOC detected Domain: inlineorcompile.call

Indicator of Compromise

XIOC detected Domain: compileschema.call

Indicator of Compromise

XIOC detected Domain: def.compile.call

Indicator of Compromise

XIOC detected Domain: it.data

Indicator of Compromise

XIOC detected Domain: subschema.data

Indicator of Compromise

XIOC detected Domain: cb.post

Indicator of Compromise

XIOC detected Domain: addref.call

Indicator of Compromise

XIOC detected Domain: addanchor.call

Indicator of Compromise

XIOC detected Domain: opts.code.es

Indicator of Compromise

XIOC detected Domain: extscope.name

Indicator of Compromise

XIOC detected Domain: gen.name

Indicator of Compromise

XIOC detected Domain: cxt.it

Indicator of Compromise

XIOC detected Domain: 1.default.data

Indicator of Compromise

XIOC detected Domain: gen.property

Indicator of Compromise

XIOC detected Domain: properties.map

Indicator of Compromise

XIOC detected Domain: def.macro.call

Indicator of Compromise

XIOC detected Domain: message.message.id

Indicator of Compromise

XIOC detected Domain: 1.name

Indicator of Compromise

XIOC detected Domain: this.opts.es

Indicator of Compromise

XIOC detected Domain: 2.name

Indicator of Compromise

XIOC detected Domain: this.to

Indicator of Compromise

XIOC detected Domain: opts.es

Indicator of Compromise

XIOC detected Domain: scope.name

Indicator of Compromise

XIOC detected Domain: message.id

Indicator of Compromise

XIOC detected Domain: errormessage.error.data

Indicator of Compromise

XIOC detected Domain: date.now

Indicator of Compromise

XIOC detected Domain: request.id

Indicator of Compromise

XIOC detected Domain: response.id

Indicator of Compromise

XIOC detected Domain: response.error.data

Indicator of Compromise

XIOC detected Domain: parseresult.data

Indicator of Compromise

XIOC detected Domain: options.name

Indicator of Compromise

XIOC detected Domain: refs.target

Indicator of Compromise

XIOC detected Domain: strategy.map

Indicator of Compromise

XIOC detected Domain: zodpatterns.email

Indicator of Compromise

XIOC detected Domain: actualkeys.map

Indicator of Compromise

XIOC detected Domain: actualvalues.map

Indicator of Compromise

XIOC detected Domain: result.properties

Indicator of Compromise

XIOC detected Domain: inst.gt

Indicator of Compromise

XIOC detected Domain: inst.lt

Indicator of Compromise

XIOC detected Domain: inst.int

Indicator of Compromise

XIOC detected Domain: inst.safe

Indicator of Compromise

XIOC detected Domain: values.map

Indicator of Compromise

XIOC detected Domain: inst.in

Indicator of Compromise

XIOC detected Domain: clientcapabilities.sampling.tools

Indicator of Compromise

XIOC detected Domain: regexes.map

Indicator of Compromise

XIOC detected Domain: mime.map

Indicator of Compromise

XIOC detected Domain: json.properties

Indicator of Compromise

XIOC detected Domain: def.items.map

Indicator of Compromise

XIOC detected Domain: checks.map

Indicator of Compromise

XIOC detected Domain: default.md

Indicator of Compromise

XIOC detected Domain: readme.md

Indicator of Compromise

XIOC detected Domain: this.it

Indicator of Compromise

XIOC detected Domain: meta.id

Indicator of Compromise

XIOC detected Domain: ctx.io

Indicator of Compromise

XIOC detected Domain: inputs.target

Indicator of Compromise

XIOC detected Domain: pm.id

Indicator of Compromise

XIOC detected Domain: ctx.target

Indicator of Compromise

XIOC detected Domain: schema.id

Indicator of Compromise

XIOC detected Domain: lines.map

Indicator of Compromise

XIOC detected Domain: content.map

Indicator of Compromise

XIOC detected Domain: r.data

Indicator of Compromise

XIOC detected Domain: catchall.run

Indicator of Compromise

XIOC detected Domain: def.options.map

Indicator of Compromise

XIOC detected Domain: patterns.map

Indicator of Compromise

XIOC detected Domain: keyresult.issues.map

Indicator of Compromise

XIOC detected Domain: def.rest

Indicator of Compromise

XIOC detected Domain: newctx.data

Indicator of Compromise

XIOC detected Domain: def.in

Indicator of Compromise

XIOC detected Domain: inst.name

Indicator of Compromise

XIOC detected Domain: issue.errors.map

Indicator of Compromise

XIOC detected Domain: zod.run

Indicator of Compromise

XIOC detected Domain: result.issues.map

Indicator of Compromise

XIOC detected Domain: result.data

Indicator of Compromise

XIOC detected Domain: schema.items.map

Indicator of Compromise

XIOC detected Domain: results.map

Indicator of Compromise

XIOC detected Domain: options.map

Indicator of Compromise

XIOC detected Domain: issues.map

Indicator of Compromise

XIOC detected Domain: sharedvalue.data

Indicator of Compromise

XIOC detected Domain: merged.data

Indicator of Compromise

XIOC detected Domain: zodparsedtype.map

Indicator of Compromise

XIOC detected Domain: zodparsedtype.date

Indicator of Compromise

XIOC detected Domain: this.name

Indicator of Compromise

XIOC detected Domain: issue.unionerrors.map

Indicator of Compromise

XIOC detected Domain: ctx.data

Indicator of Compromise

XIOC detected Domain: this.data

Indicator of Compromise

XIOC detected Domain: input.data

Indicator of Compromise

XIOC detected Domain: mathiasbynens.be

Indicator of Compromise

XIOC detected Domain: gist.github.com

Indicator of Compromise

XIOC detected Domain: www.safaribooksonline.com

Indicator of Compromise

XIOC detected Domain: spec.openapis.org

Indicator of Compromise

XIOC detected Domain: jmrware.com

Indicator of Compromise

XIOC detected Domain: object.prototype.hasownproperty.call

Indicator of Compromise

XIOC detected Domain: array.map

Indicator of Compromise

XIOC detected Domain: agents.md

Indicator of Compromise

XIOC detected Domain: github.com

Indicator of Compromise

XIOC detected Domain: stackoverflow.com

Indicator of Compromise

XIOC detected Domain: thekevinscott.com

Indicator of Compromise

XIOC detected Domain: base64.guru

Indicator of Compromise

XIOC detected Domain: blog.stevenlevithan.com

Indicator of Compromise

XIOC detected Domain: json-schema.org

Indicator of Compromise

XIOC detected Domain: enterprise.md

Indicator of Compromise

XIOC detected Domain: outcomes.md

Indicator of Compromise

XIOC detected Domain: architecture-principles.md

Indicator of Compromise

XIOC detected Domain: personal-website.md

Indicator of Compromise

XIOC detected Domain: collecstory.md

Indicator of Compromise

XIOC detected Domain: inst.email

Indicator of Compromise

XIOC detected Domain: inst.date

Indicator of Compromise

XIOC detected URL: https://github.com/dezkareid/ai-team/issues

Code Quality Issue

MCP tool poisoning risk: CODE-SMELL-dist/mcp-server/index.js-21003

Code Quality Issue

MCP tool poisoning risk: CODE-SMELL-dist/mcp-server/index.js-20948

Code Quality Issue

MCP tool poisoning risk: CODE-SMELL-dist/mcp-server/index.js-21004

Code Quality Issue

MCP tool poisoning risk: CODE-SMELL-dist/mcp-server/index.js-20971

Code Quality Issue

MCP tool poisoning risk: CODE-SMELL-dist/mcp-server/index.js-16556

metadata

HASH-92d5f62c52da3634

metadata

HASH-8cd1de6c542c60b1

metadata

HASH-a502cb2dd3653b60

metadata

HASH-73dbf425aa8cf950

metadata

HASH-cfcc06e2375c3a57

metadata

HASH-b4f27c0895bad47e

metadata

HASH-3cd6341bc6fb3f00

metadata

HASH-5cc634b5410c2663

metadata

HASH-3ce430591166cb3a

metadata

HASH-6d895c434e47c163

metadata

HASH-71e20558d4addb94

metadata

HASH-a8d43b7441692816

Recommended Action

This extension has significant security concerns that warrant careful review. Consider uninstalling or finding a safer alternative. If you must use it, limit the permissions and monitor for suspicious activity.

Analysis performed on 3/30/2026 · Version unknown

Data sourced from automated security scanning. For detailed analysis, view the full security scorecard.