detect-mcp-tool-drift
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary purpose is security monitoring. It implements detection logic for MITRE ATT&CK T1195.001 (Supply Chain Compromise) within the Model Context Protocol (MCP) ecosystem.
- [COMMAND_EXECUTION]: The skill uses standard Python subprocess-safe patterns for CLI arguments and file handling. There is no evidence of arbitrary command injection or shell execution.
- [DATA_EXFILTRATION]: No network operations (curl, wget, requests) were detected. The skill reads data from standard input or local files and writes findings to standard output.
- [PROMPT_INJECTION]: The skill instructions do not contain any patterns attempting to override agent behavior or bypass safety filters.
- [REMOTE_CODE_EXECUTION]: The skill does not download or execute remote scripts. It relies solely on the Python standard library.
Audit Metadata