MCP Integration

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of informational documentation, Markdown guides, and JSON configuration examples for educational purposes.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials or secrets were found. The skill correctly uses environment variable placeholders like ${API_KEY}, ${API_TOKEN}, and ${DB_URL} in all examples and configuration snippets.
  • [EXTERNAL_DOWNLOADS]: The skill references legitimate external resources such as the official Model Context Protocol documentation (modelcontextprotocol.io) and well-known services like Asana and GitHub for demonstration purposes.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were detected. The command examples provided (e.g., using npx) are intended for user implementation and documentation of how to configure custom MCP servers.
  • [DATA_EXFILTRATION]: No data exfiltration patterns were found. Network operation examples are limited to standard MCP transport types (SSE, HTTP, WebSocket) and include explicit security recommendations like using HTTPS/WSS.
  • [PROMPT_INJECTION]: No prompt injection attempts or instructions to bypass safety guidelines were found in the skill content or metadata.
  • [COMMAND_EXECUTION]: The skill does not contain any executable scripts or automated command execution logic that would run in the analyzer or agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 12:14 PM
Security Audit — agent-trust-hub — MCP Integration