mcp-management
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to use
npx add-mcpfrom a well-known service's repository and various vendor-specific packages (e.g.,@modelcontextprotocol/server-postgres,@github/mcp-server). These references target established organizations and well-known services. - [COMMAND_EXECUTION]: Provides instructions for executing CLI commands to add, list, and remove MCP servers using tools like
claude,npx,opencode, andcodex. It includes guidance on using environment variables and handling Windows-specific command wrappers. - [INDIRECT_PROMPT_INJECTION]: The skill manages tools (MCP servers) that ingest external data, creating an attack surface for indirect prompt injection. The documentation includes a troubleshooting section that warns users about the risks of third-party servers fetching untrusted content.
- Ingestion points: MCP tools process data from various external sources such as APIs, files, and web pages (identified in
references/search.mdandreferences/transports.md). - Boundary markers: The skill does not define specific prompt boundary markers, as it relies on the underlying agent's implementation for safety.
- Capability inventory: Capabilities include network requests, file system access, and database operations via the installed MCP servers (identified in
SKILL.mdandreferences/multi-agent.md). - Sanitization: No specific sanitization logic is provided within the skill instructions, as it focuses on configuration and management rather than data processing.
- [CREDENTIALS_SAFE]: Mentions the use of environment variables and headers for authentication but correctly uses placeholders (e.g.,
${API_KEY},TOKEN) and recommends secure practices like using native agent authentication commands (claude mcp login).
Audit Metadata