mcp-security-hub
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the primary security tool repository and container configurations from GitHub (FuzzingLabs/mcp-security-hub).
- [COMMAND_EXECUTION]: Facilitates the execution of offensive security tools through Docker commands and Docker Compose orchestration.
- [COMMAND_EXECUTION]: Configures containers with specialized network capabilities such as
NET_RAWto enable low-level packet crafting and port scanning. - [PROMPT_INJECTION]: Processes live output from external targets (e.g., HTTP responses, scan results) which represents an indirect prompt injection surface where untrusted data is fed into the agent's context.
- [COMMAND_EXECUTION]: Requires mounting local directories (e.g.,
~/projects,~/binaries) into Docker containers to perform file-based analysis and secrets detection.
Audit Metadata