native-mcp

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFENO_CODEEXTERNAL_DOWNLOADS
Full Analysis
  • [NO_CODE]: The skill consists solely of documentation and configuration guides without bundling any executable code or scripts.
  • [EXTERNAL_DOWNLOADS]: The documentation references standard installation methods for the mcp Python package and the execution of community MCP servers via trusted tools like npx and uvx.
  • [SAFE]: The skill describes a platform-native integration with explicit security controls, including environment filtering for subprocesses and error message sanitization.
  • [PROMPT_INJECTION]: The skill defines a tool discovery surface that processes data from external MCP servers. * Ingestion points: External MCP server tool definitions and call results. * Boundary markers: Not specified in the configuration. * Capability inventory: Command execution via stdio and network access via HTTP transport. * Sanitization: Automatic redaction of credentials and secret patterns from tool error messages.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 05:39 PM
Security Audit — agent-trust-hub — native-mcp