skills/aeondave/malskill/mcp-patterns/Gen Agent Trust Hub

mcp-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a documentation repository for the Model Context Protocol (MCP). It contains guidance on architecture, debugging, and implementation using the official Python SDK.
  • [DATA_EXFILTRATION]: No exfiltration patterns detected. The documentation explicitly advises against leaking secrets in logs or tool outputs and uses safe placeholders (e.g., 'replace-me') in configuration examples.
  • [SECURITY_PRACTICES]: The skill includes a dedicated security reference (references/security-boundaries.md) that emphasizes least privilege, path validation, and sanitization of external inputs.
  • [EXTERNAL_DOWNLOADS]: Dependencies mentioned (such as the mcp SDK and httpx) are official or industry-standard libraries. No untrusted remote scripts or suspicious package installations are present.
  • [COMMAND_EXECUTION]: Shell command examples are limited to standard development workflows using uv and Python, intended for local server execution as per the MCP specification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:39 PM
Security Audit — agent-trust-hub — mcp-patterns