mcp-server-orchestrator

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation and deployment of MCP servers which serve as an ingestion point for instructions from AI agents.
  • Ingestion points: Server request handlers (e.g., setRequestHandler in references/server-templates.md) receive JSON-RPC calls from clients.
  • Boundary markers: The templates utilize inputSchema to define expected data structures for tools.
  • Capability inventory: MCP servers are designed to execute tools and provide resources, which may include file system access or network operations depending on user implementation.
  • Sanitization: The skill promotes the use of JSON-RPC schemas for validation, reducing the risk of malformed input processing.
  • [COMMAND_EXECUTION]: The troubleshooting and debugging guides provide various shell commands for server management and diagnostics.
  • Evidence: Use of pkill -f "python.*mcp", tail -f ~/Library/Logs/Claude/mcp*.log, and process testing with subprocess.Popen in references/debugging-guide.md.
  • Context: These commands are standard for local development and troubleshooting of the described infrastructure.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing and running tools from external package registries.
  • Evidence: npm install -g @modelcontextprotocol/inspector, npx -y @scope/package-name, and uvx --from package-name commands found in SKILL.md and references/debugging-guide.md.
  • Context: These patterns target well-known package managers and the official protocol organization, representing standard development workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — mcp-server-orchestrator