native-mcp
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFENO_CODEEXTERNAL_DOWNLOADS
Full Analysis
- [NO_CODE]: The skill consists solely of documentation and configuration guides without bundling any executable code or scripts.
- [EXTERNAL_DOWNLOADS]: The documentation references standard installation methods for the mcp Python package and the execution of community MCP servers via trusted tools like npx and uvx.
- [SAFE]: The skill describes a platform-native integration with explicit security controls, including environment filtering for subprocesses and error message sanitization.
- [PROMPT_INJECTION]: The skill defines a tool discovery surface that processes data from external MCP servers. * Ingestion points: External MCP server tool definitions and call results. * Boundary markers: Not specified in the configuration. * Capability inventory: Command execution via stdio and network access via HTTP transport. * Sanitization: Automatic redaction of credentials and secret patterns from tool error messages.
Audit Metadata