stock-quote
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and run the 'octagon-mcp' package from the official npm registry using
npx. This is standard behavior for MCP (Model Context Protocol) servers. - [CREDENTIALS_SAFE]: The skill correctly instructs users to manage their sensitive API keys via environment variables (e.g.,
OCTAGON_API_KEY) and.envfiles rather than hardcoding them, which follows security best practices for secret management. - [COMMAND_EXECUTION]: The skill documents the specific shell commands required to initialize the Octagon MCP server within various AI agents (Cursor, Claude Desktop, Windsurf). These commands are limited to the intended functionality of the skill.
Audit Metadata