mcp-developer
Fail
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill contains metadata and instructions pointing to an external documentation site (jeffallan.github.io) which has been flagged by multiple reputation scanners as malicious.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle external data via the MCP protocol, creating a surface for indirect prompt injection. 1. Ingestion points: Tool call arguments (references/tools.md) and resource URIs (references/resources.md). 2. Boundary markers: No explicit prompt delimitation instructions are provided in the implementation snippets. 3. Capability inventory: The skill templates involve network fetching and file system operations (fs.readFile). 4. Sanitization: The skill correctly recommends Zod and Pydantic for validation and provides a directory traversal check (is_safe_path) in the reference implementations.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata