Scan result  ·  Axion (Google Earth Engine)
Axion (Google Earth Engine)

Risk

A critical issue, or a lethal-trifecta pattern, was observed on this surface.

githubscanned 4 months ago
Coverage
Medium
Tests run
3
Findings
3 rules · 4 total
Worst severity
Critical

What ran on this surface

2 categories
Tool PoisoningMCP02 · ASI02 · CoSAI-T41 finding · 0 clean
CriticalF5Official Namespace Squattingconfidence 90%

Observed: Server name.

Source
External Content
Server name "axion (google earth engine)" matches Google namespace "google" via substring...
Sink
Privilege Grant
Users approve the server on the basis of the vendor-branded name, granting it the session-...
Impact
Cross Agent Propagation
ai-client, exploitability trivial

Fix. This server's name appears to impersonate an official or well-known MCP server namespace. Rename to a unique name that clearly identifies your organization as the author. Using official-looking names...

Supply Chain SecurityMCP08 · MCP10 · ASI042 findings · 0 clean
HighD3Typosquatting Risk in Dependenciesconfidence 90% · 2 findings

Observed: Dependency npm:redis@4.

Source
External Content
Dependency npm:redis@4.7.0 is within Damerau-Levenshtein distance 2 of ioredis (threshold...
Sink
Command Execution
Malicious package `redis` executes attacker code in the build environment or at import tim...
Mitigation
Input Validation
Lockfiles pin versions but do not pin the spelling of the dependency name. The static anal...
Impact
Remote Code Execution
server-host, exploitability trivial

Fix. Verify dependency names carefully. Check that package names match the intended package exactly. Use lockfiles to prevent supply chain attacks.

HighD7Dependency Confusion Attack Riskconfidence 70%

Observed: Scoped package @types/geojson resolved at version 7946.

Source
External Content
Scoped package @types/geojson resolved at version 7946.0.16 (major 7946). Threshold: ≥99 i...
Sink
Command Execution
If @types/geojson@7946.0.16 is the public-registry impostor, its postinstall hook executes...
Mitigation
Input Validation
No registry-scope pin has been observed for @types. Without the pin the package manager re...
Impact
Remote Code Execution
server-host, exploitability moderate

Fix. Use npm/pip --registry flags to pin all installs to your private registry. Add a .npmrc with 'registry' pinned. For scoped packages, set scope-level registry configuration. Use Subresource Integrity (...

Not run on this surface
These rules could not be reached by this scan method. They stay listed and counted, so coverage is never overstated. Each says why it did not run and what would unlock it.
4Live connectionRules whose declared input (live connection) this scan method did not supply.rescan to unlock
177No execution recordNo record that these rules ran on this surface.rescan

Why these stay. The verdict is coverage aware. A clean result would read "Insufficient coverage", not "Safe", precisely because these rules did not run. Hiding them would let a shallow scan look as thorough as a deep one.

How this server was scanned

The method behind this result was not recorded: the scan predates it. How deep it reached is unknown, and is not implied by anything on this page.

Verifiable Findings

Not yet attested

This server has not been scanned with attestation enabled yet.

How to verify this yourself
# Re-run the analyzer on the signed snapshot and recompute the findings digest
curl -s https://mcp-sentinelapi-production.up.railway.app/api/v1/servers/axion-google-earth-engine/attestation.json > att.json
npx mcp-sentinel verify-scan --attestation att.json

# Prove the attestation is in the public transparency log
curl -s https://mcp-sentinelapi-production.up.railway.app/api/v1/servers/axion-google-earth-engine/attestation/inclusion.json > incl.json
npx mcp-sentinel transparency verify-inclusion --proof incl.json

Observed behaviorexecuted in sandbox

Declared tool hints vs. what each tool was actually observed to do when executed in our egress-denied sandbox - plus any witnessed tool→tool flow within this one server. This is not cross-server toxic flow, which composes several servers in one config.

Observed behavior not captured for this scan

No observed-behavior record is on file for this server's latest scan.

This is a coverage gap - we did not execute this server’s tools in the sandbox for this scan. It is not a clean result and is not scored as one. To see how observed behavior is rendered when a run does happen, view the illustrative cross-server toxic flow.

Intrinsic here, config-scoped elsewheredual unit

Everything on this page — the verdict, every finding — is Axion (Google Earth Engine) assessed on its own. That is its intrinsic posture. Whether it becomes one leg of a cross-server toxic flow is a different, config-scoped question: it depends on which other servers share its client config, and no verdict on this page changes for it.

Deepen this scan

Every link below opens a form prefilled with this server’s details. Nothing runs until you submit.

Axion (Google Earth Engine) - security audit · MCP Sentinel