capawesome-mcp

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents the use of official, vendor-owned resources (mcp.capawesome.io, cloud.capawesome.io). The domain and tools originate from the skill author ('capawesome-team') and represent expected functionality.
  • [SAFE]: The skill demonstrates best practices for credential management. In SKILL.md and references/client-setup.md, it explicitly warns users not to commit API tokens to Git, suggests using .gitignore, and recommends client-specific secure input mechanisms (like VS Code inputs prompts) or user-scoped configuration files instead of project-scoped files.
  • [EXTERNAL_DOWNLOADS]: The skill mentions mcp-remote and the npx command for Claude Desktop setup. This targets a well-known service (NPM) and is a standard method for bridging local MCP clients to remote HTTP servers; this is documented neutrally as it is a standard implementation detail for this platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 05:49 AM
Security Audit — agent-trust-hub — capawesome-mcp