mcp-skill
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use the
mcporterCLI tool through the shell to interact with various MCP servers as its primary function. - [PROMPT_INJECTION]: The skill's use of web-reading and search tools creates a surface for indirect prompt injection from untrusted external content.
- Ingestion points: External data retrieved via the
web-readerandweb-search-primeservers as described inSKILL.md. - Boundary markers: No specific delimiters or safety warnings for processing untrusted content are defined.
- Capability inventory: The skill provides access to the
mcportershell command for server interaction. - Sanitization: The skill instructions do not specify any validation or sanitization procedures for retrieved data.
Audit Metadata