windsurf-mcp-integration
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill requests broad
Bash(cmd:*)permissions to manage the lifecycle and configuration of MCP servers. This level of access is expected for a developer-focused integration tool. - [INDIRECT_PROMPT_INJECTION]: The skill integrates external data sources (databases, filesystems, APIs) via the MCP protocol. This naturally creates an attack surface where an agent could ingest untrusted data containing malicious instructions, which is a characteristic risk surface of this technology rather than a flaw in the skill itself.
- [EXTERNAL_DOWNLOADS]: The documentation references standard package managers (npm, pip) for installing MCP servers and provides links to the vendor's official websites for additional resources.
Audit Metadata