MCP Integration
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of informational documentation, Markdown guides, and JSON configuration examples for educational purposes.
- [CREDENTIALS_UNSAFE]: No hardcoded credentials or secrets were found. The skill correctly uses environment variable placeholders like
${API_KEY},${API_TOKEN}, and${DB_URL}in all examples and configuration snippets. - [EXTERNAL_DOWNLOADS]: The skill references legitimate external resources such as the official Model Context Protocol documentation (modelcontextprotocol.io) and well-known services like Asana and GitHub for demonstration purposes.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns were detected. The command examples provided (e.g., using
npx) are intended for user implementation and documentation of how to configure custom MCP servers. - [DATA_EXFILTRATION]: No data exfiltration patterns were found. Network operation examples are limited to standard MCP transport types (SSE, HTTP, WebSocket) and include explicit security recommendations like using HTTPS/WSS.
- [PROMPT_INJECTION]: No prompt injection attempts or instructions to bypass safety guidelines were found in the skill content or metadata.
- [COMMAND_EXECUTION]: The skill does not contain any executable scripts or automated command execution logic that would run in the analyzer or agent context.
Audit Metadata