mcp-management

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill spawns subprocesses to run MCP servers based on the commands and arguments specified in the .claude/.mcp.json configuration file. This is implemented via the @modelcontextprotocol/sdk and StdioClientTransport.
  • Evidence: Core logic found in scripts/mcp-client.ts and used by scripts/cli.ts.
  • [EXTERNAL_DOWNLOADS]: The documentation and configuration examples recommend using npx -y to pull official MCP server implementations directly from the npm registry at runtime.
  • Evidence: References to @modelcontextprotocol/server-memory, @modelcontextprotocol/server-filesystem, and others in README.md and references/configuration.md.
  • [REMOTE_CODE_EXECUTION]: The skill facilitates the use of high-privilege tools, such as evaluate_script (via the chrome-devtools server), which allows arbitrary JavaScript execution in a target browser. This is an intended capability of the underlying MCP servers it manages.
  • Evidence: Tool schemas documented in assets/tools.json for agent reference.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — mcp-management