fast-io

Warn

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch a remote Markdown file from https://mcp.fast.io/skill.md at the start of every session to serve as the 'complete agent guide'. This establishes a runtime dependency on an external source for the agent's core operational logic and tool parameters.
  • [DATA_EXFILTRATION]: The skill's primary function is to upload user files and data to the mcp.fast.io infrastructure. While this is the intended purpose of the service, it constitutes the transfer of potentially sensitive user information to a third-party provider.
  • [PROMPT_INJECTION]: The requirement to fetch and prioritize remote guidelines allows the remote server to dynamically alter the agent's instructions, which could be used to override local safety constraints or change behavior without a formal skill update.
  • [PROMPT_INJECTION]: There is a discrepancy between the author name listed in the skill body (fast-io) and the metadata/repository information (dbalve/Demerzels-lab), which may lead to confusion regarding the official status or security oversight of the skill.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 16, 2026, 01:00 AM
Security Audit — agent-trust-hub — fast-io