kuroco-admin-mcp
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists exclusively of documentation and configuration metadata. It does not include any executable scripts, binaries, or automated code execution patterns.
- [INDIRECT_PROMPT_INJECTION]: The skill documents an interface for processing administrative data from the Kuroco platform. While this creates a potential surface for indirect prompt injection if external content contains malicious instructions, the skill explicitly mandates human confirmation for all write operations (INSERT/UPDATE/DELETE) and encourages the use of the least-privilege principle via specific OAuth scopes (e.g.,
mcp:tools.read).
Audit Metadata