diadoc-mcp
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The installation instructions utilize the
uvxcommand to fetch and execute thediadoc-mcp-rupackage from a public registry at runtime. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill ingests untrusted data from the Diadoc API, including document content, counterparty messages, and metadata, which are processed by the agent.
- Boundary markers: The instructions do not specify any boundary markers or instructions for the agent to ignore potential malicious content embedded within the documents.
- Capability inventory: The skill provides a significant capability surface with 114 methods, including signing and sending documents.
- Sanitization: There is no evidence of sanitization or filtering of the external data before it is presented to the agent's context.
Audit Metadata