mcp-integration

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The documentation provides instructions for configuring 'stdio' MCP servers which execute local processes and scripts as child processes for tool integration.\n- [EXTERNAL_DOWNLOADS]: The skill references official and well-known MCP implementations from organizations like Asana and GitHub for service integration.\n- [INDIRECT_PROMPT_INJECTION]: The skill describes a system for ingesting data from external services (APIs, databases) which creates an attack surface for indirect prompt injection.\n
  • Ingestion points: External data processed via MCP tools as described in SKILL.md and references/tool-usage.md.\n
  • Boundary markers: The documentation recommends using tool wrappers for validation and preprocessing before data reaches the agent.\n
  • Capability inventory: The configuration supports local process execution, network operations, and file system access via configured MCP servers.\n
  • Sanitization: The skill advises developers to validate inputs and handle tool errors gracefully to mitigate risks from untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — mcp-integration