mcp-server-chart

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill communicates with the vendor's OneKey Gateway API (deepnlp.org) to process chart data and generate visualizations. This is a core functional requirement of the service.
  • [CREDENTIALS_UNSAFE]: Scripts contain a hardcoded demo API key ('BETA_TEST_KEY_MARCH_2026'). As this is explicitly documented for testing and demo purposes by the vendor, it is considered a low-risk configuration rather than a credential leak.
  • [COMMAND_EXECUTION]: Provides numerous Python scripts and a Node.js-based CLI for generating visualizations. These tools parse JSON input provided via command-line arguments or local files to pass data to the charting service.
  • [DATA_EXFILTRATION]: While the skill sends user-provided data to the vendor's servers to generate charts, this behavior is transparently documented and aligns with the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 02:40 PM
Security Audit — agent-trust-hub — mcp-server-chart