chestny-znak-mcp
Warn
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to use the
uvxtool to download and install thechestny-znak-mcp-rupackage from an external registry. - [REMOTE_CODE_EXECUTION]: The configuration launches the
crpt-mcpserver directly from the downloaded package, executing remote code on the host system. - [INDIRECT_PROMPT_INJECTION]: The skill retrieves structured data from the Chestny Znak (GIS MT) and SUZ APIs, which is then processed by the AI agent. This creates a vulnerability where malicious content in the external API responses could influence the agent's behavior.
- Ingestion points: Data from 33 methods related to marking codes, emission orders, and product routes (SKILL.md).
- Boundary markers: No specific delimiters or safety instructions are defined to separate tool output from system instructions.
- Capability inventory: The skill allows the agent to read and process external system data and manage orders.
- Sanitization: No evidence of sanitization or validation of the API content before it is provided to the agent.
Audit Metadata