mcp-developer
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a technical reference for building and debugging MCP integrations. It references official and well-known development tools such as the @modelcontextprotocol/sdk, mcp, and the official MCP inspector.
- [DATA_EXPOSURE_AND_EXFILTRATION]: While the skill contains examples for accessing file systems and databases, these are provided as pedagogical templates. The instructions explicitly warn against exposing sensitive data and demonstrate security controls like path traversal checks (e.g., ensuring a resolved path starts within an ALLOWED_DIR).
- [COMMAND_EXECUTION]: The skill documents the use of standard project initialization and debugging commands (npx, pip). These commands are relevant to the skill's purpose as a developer tool and target official package registries.
- [INDIRECT_PROMPT_INJECTION]: The skill provides guidance on handling external data via JSON-RPC. It mitigates injection risks by instructing developers to use strict schema validation (Zod and Pydantic) for all tool inputs and resource URIs, which prevents the agent from executing unvalidated instructions embedded in data.
Audit Metadata