connect-mcps

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests data from external sources, such as web search results and MCP tool outputs, to update workspace configuration files.
  • Ingestion points: Research results for documentation (Steps 2, 3, 11) and tool capability data from MCP servers (Step 5).
  • Boundary markers: No delimiters are specified for content written to SKILL.md or pm/CLAUDE.md.
  • Capability inventory: The skill modifies existing skill files and workspace configuration.
  • Sanitization: No explicit validation or escaping of ingested data is described before persistence.
  • [DATA_EXFILTRATION]: The skill workflow involves collecting sensitive credentials like API keys and tokens. While the skill instructions state these are not saved to files, they are handled in the agent's context during the setup process.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 12:58 AM
Security Audit — agent-trust-hub — connect-mcps