mcp-provider
Pass
Audited by Gen Agent Trust Hub on Apr 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed as a management tool for MCP integrations and incorporates multiple security features including runtime isolation and manifest validation.\n- [COMMAND_EXECUTION]: The Python scripts (
discover_mcp.py,attach_mcp.py, andtest_mcp.py) execute standard file system operations to manage tool configurations and metadata within the project's skill directory structure.\n- [EXTERNAL_DOWNLOADS]: The skill references official MCP server repositories on GitHub for tool discovery. These are well-known, trusted industry sources and do not involve automated script execution via shell piping.\n- [DATA_EXFILTRATION]: No unauthorized network operations or data harvesting patterns were detected. The documentation explicitly advises against committing secrets to version control and provides templates for secure environment management.
Audit Metadata