mcp-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a documentation repository for the Model Context Protocol (MCP). It contains guidance on architecture, debugging, and implementation using the official Python SDK.
- [DATA_EXFILTRATION]: No exfiltration patterns detected. The documentation explicitly advises against leaking secrets in logs or tool outputs and uses safe placeholders (e.g., 'replace-me') in configuration examples.
- [SECURITY_PRACTICES]: The skill includes a dedicated security reference (
references/security-boundaries.md) that emphasizes least privilege, path validation, and sanitization of external inputs. - [EXTERNAL_DOWNLOADS]: Dependencies mentioned (such as the
mcpSDK andhttpx) are official or industry-standard libraries. No untrusted remote scripts or suspicious package installations are present. - [COMMAND_EXECUTION]: Shell command examples are limited to standard development workflows using
uvand Python, intended for local server execution as per the MCP specification.
Audit Metadata