skills/aeondave/malskill/mcp-creator/Gen Agent Trust Hub

mcp-creator

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a local utility script scripts/check_mcp_conformance.py and provides explicit instructions for the agent to execute it using the Python interpreter to analyze server source code.
  • [INDIRECT_PROMPT_INJECTION]: The conformance checker script performs static analysis on external files provided by the user, creating a surface where malicious instructions embedded in the analyzed code could potentially influence the agent's subsequent review of the findings.
  • Ingestion points: The script reads file content from a user-specified directory via scripts/check_mcp_conformance.py.
  • Boundary markers: None identified in the script's reporting output.
  • Capability inventory: The script is limited to file system read access for analysis purposes; it contains no file-write, network, or privileged execution capabilities.
  • Sanitization: None; the script performs raw text analysis using regular expressions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:20 PM
Security Audit — agent-trust-hub — mcp-creator