kuroco-admin-mcp

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists exclusively of documentation and configuration metadata. It does not include any executable scripts, binaries, or automated code execution patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents an interface for processing administrative data from the Kuroco platform. While this creates a potential surface for indirect prompt injection if external content contains malicious instructions, the skill explicitly mandates human confirmation for all write operations (INSERT/UPDATE/DELETE) and encourages the use of the least-privilege principle via specific OAuth scopes (e.g., mcp:tools.read).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 02:15 AM
Security Audit — agent-trust-hub — kuroco-admin-mcp