mcp-server-attack-probe

Warn

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to attempt shell command injection using metadata characters and payloads such as ; id and $(id) when testing shell-shaped tools.
  • [DATA_EXFILTRATION]: Provides specific probes for accessing sensitive system files and credentials, including /etc/passwd, .env, and ~/.aws via path traversal techniques.
  • [REMOTE_CODE_EXECUTION]: Includes instructions to perform SSRF (Server-Side Request Forgery) attacks targeting internal cloud metadata services (169.254.169.254) and local loopback services like Redis and Memcached.
  • [EXTERNAL_DOWNLOADS]: References official Model Context Protocol SDKs and documentation from GitHub repositories and official project domains.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 13, 2026, 12:44 PM
Security Audit — agent-trust-hub — mcp-server-attack-probe