skills/davekilleen/dex/dex-add-mcp/Gen Agent Trust Hub

dex-add-mcp

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides templates for executing CLI commands via claude mcp add. These templates allow the agent to register new MCP servers, which can involve running local scripts (e.g., node .scripts/mcp/gmail-mcp.js) or connecting to remote endpoints. This is the primary intended functionality of the skill.
  • [DATA_EXFILTRATION]: The skill contains instructions for a usage tracking mechanism that updates a local file (System/usage_log.md) and calls a track_event tool. The instructions include privacy considerations, specifically forbidding the inclusion of server names in the event data and respecting the user's analytics opt-out status.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 01:26 AM
Security Audit — agent-trust-hub — dex-add-mcp