alchemy-mcp

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a configuration guide for the hosted Alchemy MCP server at https://mcp.alchemy.com/mcp. No malicious code, unauthorized access, or exfiltration patterns were detected. Authentication is handled via standard OAuth 2.1 by the AI client.
  • [EXTERNAL_DOWNLOADS]: Mentions the @alchemy/cli package as a local installation alternative. This is an official tool provided by the vendor.
  • [COMMAND_EXECUTION]: Provides standard shell commands for users to manually configure their MCP clients (e.g., claude mcp add). These are legitimate setup procedures for the protocol and do not involve hidden or dangerous code execution.
  • [SAFE]: The skill possesses an indirect prompt injection surface as it ingests untrusted blockchain data (via tools like ethGetLogs, getNFTMetadata, and traceTransaction) and has capabilities to manage apps (via create_app and update_allowlist). No specific boundary markers or sanitization logic are defined in the instructions, but the risk is inherent to the blockchain explorer use case and is mediated by the vendor's hosted environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 10:30 AM
Security Audit — agent-trust-hub — alchemy-mcp