mcp-integration-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes building MCP servers that ingest data from external sources (e.g., databases, files, APIs) and expose it to an AI assistant, creating a surface for indirect prompt injection.
  • Ingestion points: The server implementations in SKILL.md and references/server-examples.md include tools and resources that process user-supplied arguments and retrieve content from external files and database tables.
  • Boundary markers: The prompt templates in SKILL.md use markdown backticks to wrap code but do not provide instructions to the AI to disregard instructions within that code.
  • Capability inventory: The skill demonstrates capabilities including reading and writing to the local file system and executing SQL queries.
  • Sanitization: The examples show defensive practices such as path resolution via Path.resolve() to prevent traversal and keyword filtering to block destructive SQL operations.
  • [COMMAND_EXECUTION]: The documentation outlines how to configure AI assistants to execute local server processes via the stdio transport protocol.
  • Evidence: SKILL.md and references/deployment-patterns.md provide configuration examples for claude_desktop_config.json that use the command and args fields to launch subprocesses.
  • [EXTERNAL_DOWNLOADS]: The documentation suggests using package managers to download and run code from external registries.
  • Evidence: references/deployment-patterns.md illustrates the use of npx -y @myorg/my-mcp-server and uv run to initialize and run MCP servers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — mcp-integration-patterns