multi-llm-mcp-server

Fail

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The 'ask_codex' tool features a 'danger-full-access' sandbox mode that provides full system access, enabling the execution of arbitrary shell commands such as dependency installation or test execution. This allows an AI agent to perform unrestricted actions on the host system.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its core data-handling workflows. -- Ingestion points: The skill instructs the agent to read and process local files (e.g., via the 'review' tool and 'ask_codex' analysis tasks). -- Boundary markers: No delimiters or instructions are provided to distinguish between legitimate content and potentially malicious instructions embedded within processed files. -- Capability inventory: The skill provides powerful tools for file modification ('workspace-write') and full system access ('danger-full-access'). -- Sanitization: There is no evidence of sanitization or validation of ingested file content before it is passed to LLM models or execution tools.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 15, 2026, 01:04 AM
Security Audit — agent-trust-hub — multi-llm-mcp-server