mcp-management
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill spawns subprocesses to run MCP servers based on the commands and arguments specified in the
.claude/.mcp.jsonconfiguration file. This is implemented via the@modelcontextprotocol/sdkandStdioClientTransport. - Evidence: Core logic found in
scripts/mcp-client.tsand used byscripts/cli.ts. - [EXTERNAL_DOWNLOADS]: The documentation and configuration examples recommend using
npx -yto pull official MCP server implementations directly from the npm registry at runtime. - Evidence: References to
@modelcontextprotocol/server-memory,@modelcontextprotocol/server-filesystem, and others inREADME.mdandreferences/configuration.md. - [REMOTE_CODE_EXECUTION]: The skill facilitates the use of high-privilege tools, such as
evaluate_script(via thechrome-devtoolsserver), which allows arbitrary JavaScript execution in a target browser. This is an intended capability of the underlying MCP servers it manages. - Evidence: Tool schemas documented in
assets/tools.jsonfor agent reference.
Audit Metadata