chestny-znak-mcp

Warn

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to use the uvx tool to download and install the chestny-znak-mcp-ru package from an external registry.
  • [REMOTE_CODE_EXECUTION]: The configuration launches the crpt-mcp server directly from the downloaded package, executing remote code on the host system.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves structured data from the Chestny Znak (GIS MT) and SUZ APIs, which is then processed by the AI agent. This creates a vulnerability where malicious content in the external API responses could influence the agent's behavior.
  • Ingestion points: Data from 33 methods related to marking codes, emission orders, and product routes (SKILL.md).
  • Boundary markers: No specific delimiters or safety instructions are defined to separate tool output from system instructions.
  • Capability inventory: The skill allows the agent to read and process external system data and manage orders.
  • Sanitization: No evidence of sanitization or validation of the API content before it is provided to the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 11, 2026, 10:51 AM
Security Audit — agent-trust-hub — chestny-znak-mcp