analyze-mcp-server

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is authored by Amplitude and utilizes official Amplitude connectors and tools to perform analysis on telemetry data associated with the user's project. All data retrieval and processing are consistent with the stated purpose of generating MCP usage and error reports. No unauthorized network operations or file system access were identified.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted natural language data from the [MCP] Rationale event property, which could theoretically contain instructions intended to influence the agent's analysis. However, given the skill's limited capabilities, the risk is negligible.\n
  • Ingestion points: Event data ([MCP] Tool Call Response) fetched from the Amplitude project via the Amplitude connector, specifically rationale and error message strings.\n
  • Boundary markers: The instructions do not define specific delimiters for processed rationales within the analysis prompt.\n
  • Capability inventory: Limited to Amplitude context tools, segmentation queries, and report generation. No shell access, arbitrary code execution, or file modification tools are requested.\n
  • Sanitization: The skill performs intent-based clustering and summarization of the retrieved data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 03:09 AM
Security Audit — agent-trust-hub — analyze-mcp-server