mcp-developer

Fail

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill contains metadata and instructions pointing to an external documentation site (jeffallan.github.io) which has been flagged by multiple reputation scanners as malicious.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle external data via the MCP protocol, creating a surface for indirect prompt injection. 1. Ingestion points: Tool call arguments (references/tools.md) and resource URIs (references/resources.md). 2. Boundary markers: No explicit prompt delimitation instructions are provided in the implementation snippets. 3. Capability inventory: The skill templates involve network fetching and file system operations (fs.readFile). 4. Sanitization: The skill correctly recommends Zod and Pydantic for validation and provides a directory traversal check (is_safe_path) in the reference implementations.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 6, 2026, 11:36 AM
Security Audit — agent-trust-hub — mcp-developer