mcp-provider

Pass

Audited by Gen Agent Trust Hub on Apr 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed as a management tool for MCP integrations and incorporates multiple security features including runtime isolation and manifest validation.\n- [COMMAND_EXECUTION]: The Python scripts (discover_mcp.py, attach_mcp.py, and test_mcp.py) execute standard file system operations to manage tool configurations and metadata within the project's skill directory structure.\n- [EXTERNAL_DOWNLOADS]: The skill references official MCP server repositories on GitHub for tool discovery. These are well-known, trusted industry sources and do not involve automated script execution via shell piping.\n- [DATA_EXFILTRATION]: No unauthorized network operations or data harvesting patterns were detected. The documentation explicitly advises against committing secrets to version control and provides templates for secure environment management.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 17, 2026, 03:02 PM