jfrog-mcp-management

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and executes the @jfrog/agent-guard package from the official JFrog Artifactory registry (https://releases.jfrog.io/artifactory/api/npm/coding-agents-npm/) using npx.
  • [COMMAND_EXECUTION]: Executes local Node.js scripts to perform mandatory environment checks and verify the activation status of the JFrog Agent Guard.
  • [COMMAND_EXECUTION]: Utilizes the jf CLI to securely export platform configuration and resolve server credentials for authentication with the JFrog platform.
  • [PROMPT_INJECTION]: Instructs the agent to perform startup checks silently to maintain a clean user interface.
  • [PROMPT_INJECTION]: Mandates a strict installation workflow that requires the agent to prioritize the JFrog governed catalog and ignore installation instructions from external MCP documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 04:03 PM
Security Audit — agent-trust-hub — jfrog-mcp-management