mksc-methods

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of markdown-based instructions for choosing research methodologies. It does not contain any executable scripts, shell commands, or subprocess calls.
  • [SAFE]: No evidence of data exfiltration or credential harvesting was detected. All file references (e.g., ../../../shared-resources/empirical-methods/execution-with-mcp.md) are relative paths within the local project structure, which is standard for documentation.
  • [SAFE]: The skill mentions external statistical tools (e.g., rdrobust, bacon_decomposition) but explicitly states that it "does not execute the estimation," serving only as a design framework rather than an execution engine.
  • [SAFE]: While the skill involves processing user-provided manuscript content (Indirect Prompt Injection surface), it lacks any exploitable capabilities such as network access, file system writes, or arbitrary code execution that would permit a malicious payload to be effective.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 11:57 PM
Security Audit — agent-trust-hub — mksc-methods