mcp-server-attack-probe
Warn
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to attempt shell command injection using metadata characters and payloads such as
; idand$(id)when testing shell-shaped tools. - [DATA_EXFILTRATION]: Provides specific probes for accessing sensitive system files and credentials, including
/etc/passwd,.env, and~/.awsvia path traversal techniques. - [REMOTE_CODE_EXECUTION]: Includes instructions to perform SSRF (Server-Side Request Forgery) attacks targeting internal cloud metadata services (169.254.169.254) and local loopback services like Redis and Memcached.
- [EXTERNAL_DOWNLOADS]: References official Model Context Protocol SDKs and documentation from GitHub repositories and official project domains.
Audit Metadata