mcp-release-qa

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill instructs the agent to execute build and installation procedures defined in the project being tested (e.g., via Makefile or npm). This is the intended purpose of the QA skill, and it includes guidelines to use fixtures or sandboxed environments to protect production data.
  • [DATA_EXPOSURE]: The skill requires capturing raw responses and environment details for evidence. It mitigates exposure risks by explicitly instructing the agent to redact credentials, secrets, and sensitive environment variable values from all reports.
  • [INDIRECT_PROMPT_INJECTION]: The agent ingests output from the server under test. Potential influence from malicious server responses is mitigated by instructions to verify runtime behavior against the source code definitions and documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 05:55 PM
Security Audit — agent-trust-hub — mcp-release-qa