mcp-implementation-security-review

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns or executable code detected. The skill is entirely composed of markdown instructions and reference tables for human or agent-led security reviews.- [PROMPT_INJECTION]: The skill is designed to audit untrusted third-party source code, creating a surface for indirect prompt injection (Category 8) where malicious content in the audited files could attempt to influence the agent's behavior or findings. This risk is inherent to the skill's primary purpose.
  • Ingestion points: Processes implementation source code of MCP servers, clients, and tool handlers.
  • Boundary markers: None explicitly defined within the audit instructions.
  • Capability inventory: The skill contains no executable scripts, subprocess calls, or system-modifying commands.
  • Sanitization: No input sanitization steps are specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 09:53 PM
Security Audit — agent-trust-hub — mcp-implementation-security-review