mcp-management

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's primary function is to spawn and manage MCP servers as subprocesses. In scripts/mcp-client.ts, the StdioClientTransport is used to execute commands and arguments defined in the user's configuration file (.claude/.mcp.json). While this is the intended behavior for an MCP client, it involves the execution of arbitrary system commands defined in the configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes outputs from external MCP servers, including tool results, prompts, and resources. This creates a surface where malicious or unexpected data from a connected server could influence the agent's behavior.
  • Ingestion points: Data enters the system through scripts/mcp-client.ts via methods like getAllTools, getAllPrompts, getAllResources, and callTool.
  • Boundary markers: The provided scripts do not implement specific delimiters or instructions to the agent to treat server-provided content as untrusted data.
  • Capability inventory: The skill can spawn subprocesses and execute tools with arbitrary JSON-serializable parameters across multiple servers.
  • Sanitization: There is no evidence of explicit sanitization or filtering of data received from MCP servers before it is returned to the agent.
  • [EXTERNAL_DOWNLOADS]: The documentation (README.md, SKILL.md, and references/gemini-cli-integration.md) recommends the installation of external software, such as the gemini-cli package and various MCP servers (e.g., @modelcontextprotocol/server-memory, @modelcontextprotocol/server-filesystem) using package managers like npm and npx.
  • [DYNAMIC_EXECUTION]: The pre-populated tool catalog in assets/tools.json references a chrome-devtools server that provides an evaluate_script tool. This tool allows for the execution of arbitrary JavaScript code within a browser context, which is a powerful dynamic execution capability.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:15 AM
Security Audit — agent-trust-hub — mcp-management