jfrog-mcp-management
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches and executes the @jfrog/agent-guard package from the official JFrog Artifactory registry (https://releases.jfrog.io/artifactory/api/npm/coding-agents-npm/) using npx.
- [COMMAND_EXECUTION]: Executes local Node.js scripts to perform mandatory environment checks and verify the activation status of the JFrog Agent Guard.
- [COMMAND_EXECUTION]: Utilizes the jf CLI to securely export platform configuration and resolve server credentials for authentication with the JFrog platform.
- [PROMPT_INJECTION]: Instructs the agent to perform startup checks silently to maintain a clean user interface.
- [PROMPT_INJECTION]: Mandates a strict installation workflow that requires the agent to prioritize the JFrog governed catalog and ignore installation instructions from external MCP documentation.
Audit Metadata