mcp-security

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a security auditing and implementation guide for MCP servers, prioritizing defensive coding practices and least-privilege principles.
  • [PROMPT_INJECTION]: The static analysis hits in references/sharp_edges.md for patterns like "ignore previous instructions" are false positives. These strings are contained within the sanitizeForAI logic and documentation intended to teach the agent how to recognize and filter out malicious inputs from tool outputs rather than executing them.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a comprehensive defense strategy for indirect prompt injection. It identifies tool outputs as the primary ingestion point (e.g., handleReadFile in sharp_edges.md), mandates the use of boundary markers ([BEGIN USER DATA]), and includes specific sanitization functions to strip instruction-like phrases from data before it reaches the AI context.
  • [EXTERNAL_DOWNLOADS]: The skill mentions standard, well-known Node.js libraries such as zod, ioredis, and rate-limiter-flexible. These are reputable packages commonly used for the defensive patterns (validation and rate limiting) described in the reference files.
  • [CREDENTIALS_UNSAFE]: The skill actively discourages hardcoding secrets and provides validation rules in references/validations.md to detect hardcoded keys in user code, recommending environment variables as the safe alternative.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:18 PM
Security Audit — agent-trust-hub — mcp-security