mcp-management
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's primary function is to spawn and manage MCP servers as subprocesses. In
scripts/mcp-client.ts, theStdioClientTransportis used to execute commands and arguments defined in the user's configuration file (.claude/.mcp.json). While this is the intended behavior for an MCP client, it involves the execution of arbitrary system commands defined in the configuration. - [INDIRECT_PROMPT_INJECTION]: The skill processes outputs from external MCP servers, including tool results, prompts, and resources. This creates a surface where malicious or unexpected data from a connected server could influence the agent's behavior.
- Ingestion points: Data enters the system through
scripts/mcp-client.tsvia methods likegetAllTools,getAllPrompts,getAllResources, andcallTool. - Boundary markers: The provided scripts do not implement specific delimiters or instructions to the agent to treat server-provided content as untrusted data.
- Capability inventory: The skill can spawn subprocesses and execute tools with arbitrary JSON-serializable parameters across multiple servers.
- Sanitization: There is no evidence of explicit sanitization or filtering of data received from MCP servers before it is returned to the agent.
- [EXTERNAL_DOWNLOADS]: The documentation (
README.md,SKILL.md, andreferences/gemini-cli-integration.md) recommends the installation of external software, such as thegemini-clipackage and various MCP servers (e.g.,@modelcontextprotocol/server-memory,@modelcontextprotocol/server-filesystem) using package managers likenpmandnpx. - [DYNAMIC_EXECUTION]: The pre-populated tool catalog in
assets/tools.jsonreferences achrome-devtoolsserver that provides anevaluate_scripttool. This tool allows for the execution of arbitrary JavaScript code within a browser context, which is a powerful dynamic execution capability.
Audit Metadata