mcp-security
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a security auditing and implementation guide for MCP servers, prioritizing defensive coding practices and least-privilege principles.
- [PROMPT_INJECTION]: The static analysis hits in
references/sharp_edges.mdfor patterns like "ignore previous instructions" are false positives. These strings are contained within thesanitizeForAIlogic and documentation intended to teach the agent how to recognize and filter out malicious inputs from tool outputs rather than executing them. - [INDIRECT_PROMPT_INJECTION]: The skill provides a comprehensive defense strategy for indirect prompt injection. It identifies tool outputs as the primary ingestion point (e.g.,
handleReadFileinsharp_edges.md), mandates the use of boundary markers ([BEGIN USER DATA]), and includes specific sanitization functions to strip instruction-like phrases from data before it reaches the AI context. - [EXTERNAL_DOWNLOADS]: The skill mentions standard, well-known Node.js libraries such as
zod,ioredis, andrate-limiter-flexible. These are reputable packages commonly used for the defensive patterns (validation and rate limiting) described in the reference files. - [CREDENTIALS_UNSAFE]: The skill actively discourages hardcoding secrets and provides validation rules in
references/validations.mdto detect hardcoded keys in user code, recommending environment variables as the safe alternative.
Audit Metadata