mcp-mastery

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides links to and instructions for downloading MCP servers from various external repositories. These include official implementations from trusted organizations such as Anthropic, Microsoft, GitHub, Cloudflare, and Supabase, which are used to extend the agent's functionality to external systems like databases, Slack, and cloud infrastructure.
  • [COMMAND_EXECUTION]: The skill includes instructions for installing tools using claude mcp add, npx, and uvx. These commands allow users to configure and connect new MCP servers to their environment. The instructions include placeholders for API keys and configuration paths, following standard documentation patterns for the Model Context Protocol.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The instructions reference local configuration files such as ~/.claude.json and .mcp.json. This access is intended for managing, listing, and verifying the state of connected MCP servers as part of the skill's primary advisory role.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:07 PM
Security Audit — agent-trust-hub — mcp-mastery