mcp-integration-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes building MCP servers that ingest data from external sources (e.g., databases, files, APIs) and expose it to an AI assistant, creating a surface for indirect prompt injection.
- Ingestion points: The server implementations in
SKILL.mdandreferences/server-examples.mdinclude tools and resources that process user-supplied arguments and retrieve content from external files and database tables. - Boundary markers: The prompt templates in
SKILL.mduse markdown backticks to wrap code but do not provide instructions to the AI to disregard instructions within that code. - Capability inventory: The skill demonstrates capabilities including reading and writing to the local file system and executing SQL queries.
- Sanitization: The examples show defensive practices such as path resolution via
Path.resolve()to prevent traversal and keyword filtering to block destructive SQL operations. - [COMMAND_EXECUTION]: The documentation outlines how to configure AI assistants to execute local server processes via the
stdiotransport protocol. - Evidence:
SKILL.mdandreferences/deployment-patterns.mdprovide configuration examples forclaude_desktop_config.jsonthat use thecommandandargsfields to launch subprocesses. - [EXTERNAL_DOWNLOADS]: The documentation suggests using package managers to download and run code from external registries.
- Evidence:
references/deployment-patterns.mdillustrates the use ofnpx -y @myorg/my-mcp-serveranduv runto initialize and run MCP servers.
Audit Metadata