mcp-server-integration
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external MCP server definitions and tool configurations, creating a potential attack surface.
- Ingestion points: The skill consumes 'MCP server details', 'connection configuration', and 'tool definitions' as inputs (SKILL.md).
- Boundary markers: There are no explicit instructions to use delimiters or warnings to ignore instructions embedded within the configuration data.
- Capability inventory: The skill enables the registration of tools and server connections, which are significant capabilities if configured with malicious intent.
- Sanitization: The steps do not explicitly include validation, sanitization, or filtering of the provided server and tool specifications.
Audit Metadata