mcp-ecosystem-optimizer
Warn
Audited by Gen Agent Trust Hub on Jun 27, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill recommends installing and executing code from third-party repositories via package managers. Examples include 'pip install mcp-serverman' and 'npx @bryan-thompson/dashboard', which pull code from sources maintained by individual users on PyPI and NPM.
- [EXTERNAL_DOWNLOADS]: It encourages cloning and integrating multiple open-source tools from GitHub, such as 'jlowin/fastmcp' and 'gomcpgo/api-wrapper-mcp', which are not from trusted or well-known service providers.
- [COMMAND_EXECUTION]: Core workflows involve executing shell commands for system configuration and tool management, such as 'docker-compose up' for monitoring stacks and 'manus-mcp-cli' for server inventory.
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it processes data from public registries and GitHub search results. Ingestion points include directories like Glama AI and PulseMCP mentioned in 'references/mcp-registries.md'. Capability inventory includes file-writing and automated command execution through generated plans. Boundary markers and sanitization steps are absent in the workflow, allowing external content to influence agent plans directly.
- [SAFE]: Downloads and configurations involving the official Supabase GitHub organization are from a well-known service and are documented neutrally.
Audit Metadata