italian-parliament-mcp

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate extension for querying official Italian government data. All tools reference public SPARQL endpoints maintained by the Camera dei Deputati and Senato della Repubblica.- [DATA_EXPOSURE]: No hardcoded secrets, API keys, or sensitive file paths (e.g., .ssh, .aws) were identified. The skill correctly manages configuration via the MCP server environment.- [PROMPT_INJECTION]: The instructions include strong grounding rules that require the agent to strictly report data returned by tools, avoiding confabulation or the creation of placeholder values.- [INDIRECT_PROMPT_INJECTION]: The skill processes external text data from parliamentary bills, speeches, and audits. While this represents a potential surface for indirect injection, the risk is inherent to the data-retrieval purpose. The author has mitigated this risk by including explicit instructions to distinguish between tool-provided data and agent interpretation, and by requiring citations for specific data points.- [COMMAND_EXECUTION]: The documentation mentions a local CLI utility for fetching specific bill texts that are protected by anti-bot measures (AWS WAF). This is a user-controlled local tool and does not constitute silent or unsafe command execution by the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 03:26 PM
Security Audit — agent-trust-hub — italian-parliament-mcp