skillhub-mcp
Unknown developer
Threat Summary
Key Security Threats
MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-21530
dist/index.js:21530
YARA rule match: -postinstall_obfuscation
/tmp/extract-b9d84d07518dd915f887253590615f8af11c0a032e00884f13c370ef6883a8a3-3672626142/SECURITY.md
YARA rule match: -NoUseEval
/tmp/extract-b9d84d07518dd915f887253590615f8af11c0a032e00884f13c370ef6883a8a3-3672626142/SECURITY.md
YARA rule match: -postinstall_network_communication
/tmp/extract-b9d84d07518dd915f887253590615f8af11c0a032e00884f13c370ef6883a8a3-3672626142/SECURITY.md
YARA rule match: -postinstall_file_download
/tmp/extract-b9d84d07518dd915f887253590615f8af11c0a032e00884f13c370ef6883a8a3-3672626142/SECURITY.md
All Findings (37)
View all 37 security findings
MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-21530
YARA rule match: -postinstall_obfuscation
YARA rule match: -NoUseEval
YARA rule match: -postinstall_network_communication
YARA rule match: -postinstall_file_download
YARA rule match: -postinstall_system_command
MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-21913
MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-21941
MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-21934
YARA rule match: -NoUseEval
YARA rule match: -postinstall_network_communication
YARA rule match: -UsingShellInterpreterWhenExecutingOSCommands
YARA rule match: -postinstall_file_manipulation
YARA rule match: -postinstall_system_command
MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-21920
MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-9375
MCP tool poisoning risk: CREDENTIAL-ACCESS-dist/index.js-6536
YARA rule match: -credential_env_files
YARA rule match: -postinstall_persistence_mechanism
YARA rule match: -NoUseWeakRandom
YARA rule match: -postinstall_crypto_operations
YARA rule match: -postinstall_obfuscation
YARA rule match: -UsingCommandLineArguments
YARA rule match: -postinstall_file_manipulation
YARA rule match: -postinstall_network_communication
YARA rule match: -postinstall_file_download
YARA rule match: -postinstall_registry_modification
YARA rule match: -postinstall_system_command
YARA rule match: -postinstall_obfuscation
YARA rule match: -UsingCommandLineArguments
YARA rule match: -postinstall_system_command
YARA rule match: -postinstall_crypto_operations
HASH-6e191c1c7e55b4b7
HASH-b7017b449c38174e
HASH-49481e063fcf24eb
HASH-63a556c2ab8c8343
HASH-39ddfa4f9561a668
Recommended Action
This extension has significant security concerns that warrant careful review. Consider uninstalling or finding a safer alternative. If you must use it, limit the permissions and monitor for suspicious activity.