mcp-server-setup

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a documentation guideline for environment setup and does not contain executable code or malicious instructions.
  • [SAFE]: Credential handling instructions recommend storing sensitive information like API keys and tokens in ~/.devcontainer-state/, which is explicitly noted as being excluded from version control (gitignored). This aligns with security best practices for local development.
  • [SAFE]: The command execution examples, such as using npx to test MCP servers, are standard methods for interacting with these protocols and are presented in the context of manual testing by the developer.
  • [SAFE]: No obfuscation, data exfiltration, or unauthorized privilege escalation patterns were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 03:28 PM
Security Audit — agent-trust-hub — mcp-server-setup