Skip to content

False-positive OSM malware listing evidence for proxyclaw-mcp-server #1

@IPloop-dev

Description

@IPloop-dev

OpenSourceMalware currently lists proxyclaw-mcp-server as malicious under record:

e3f80a07-5f4f-492a-9ba5-f7f6c80ca806

This is a false positive. We have requested that OSM either provide the exact private payload indicator/evidence or remove/reclassify the record.

Package

Reproducible build evidence

Current PyPI artifacts are reproducibly built from public source. A clean local rebuild produced artifacts matching PyPI exactly:

  • Wheel hash matches PyPI: 3f81959d...
  • Sdist hash matches PyPI: 1180d6bb...

Static review evidence

Static review found:

  • No install hooks
  • No shell execution
  • No obfuscation
  • No credential exfiltration
  • Runtime secret access is limited to IPLOOP_API_KEY

Request to OpenSourceMalware

Please provide the private payload indicator/evidence for this classification, or remove/reclassify the record.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions