detect-mcp-tool-drift

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary purpose is security monitoring. It implements detection logic for MITRE ATT&CK T1195.001 (Supply Chain Compromise) within the Model Context Protocol (MCP) ecosystem.
  • [COMMAND_EXECUTION]: The skill uses standard Python subprocess-safe patterns for CLI arguments and file handling. There is no evidence of arbitrary command injection or shell execution.
  • [DATA_EXFILTRATION]: No network operations (curl, wget, requests) were detected. The skill reads data from standard input or local files and writes findings to standard output.
  • [PROMPT_INJECTION]: The skill instructions do not contain any patterns attempting to override agent behavior or bypass safety filters.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute remote scripts. It relies solely on the Python standard library.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:17 AM
Security Audit — agent-trust-hub — detect-mcp-tool-drift