cf-add-integration
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to execute local Python scripts (
scripts/connector-status.py) and perform external metadata checks vianpm viewto verify the existence and versioning of third-party packages. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external and local sources, creating a surface for indirect prompt injection where malicious instructions could be embedded in package metadata or reference files.
- Ingestion points: Content is ingested from the
.mcp.json.connectors-referencefile, the output of thenpm viewcommand, and user-provided service names. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified for the ingested content.
- Capability inventory: The skill environment permits command execution using
pythonandnpmtools. - Sanitization: The instructions do not detail specific sanitization or validation routines for data retrieved from the npm registry or reference files before processing.
Audit Metadata