awesome-mcp-servers-discovery

Fail

Audited by Snyk on May 17, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The prompt includes examples that embed credentials verbatim (connection strings with passwords, a .env showing ghp_/sk_-style tokens, and commands like echo $GITHUB_TOKEN), which encourages exposing secrets directly rather than keeping them only in environment variables or secure tools.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The SKILL.md explicitly instructs fetching and inspecting public, user-generated sources—e.g., "git clone https://github.com/YuzeHao2023/Awesome-MCP-Servers", "Browse https://github.com/...", "Check Issues and Discussions tabs on GitHub", and use of mcp-cli inspect and AgentQL/fetch servers—so the agent is expected to read and act on untrusted third-party content that could influence tool use and decisions.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.70). The skill includes instructions that change system ownership/permissions (chown root:mcp, chmod 500), write logs to /var/log, and recommend global installs (npm install -g) and configuration of system-level services—actions that modify machine state and often require sudo/elevated privileges.

Issues (3)

W007
HIGH

Insecure credential handling detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
May 17, 2026, 04:24 PM
Issues
3
Security Audit — snyk — awesome-mcp-servers-discovery