mcp-server-integration

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external MCP server definitions and tool configurations, creating a potential attack surface.
  • Ingestion points: The skill consumes 'MCP server details', 'connection configuration', and 'tool definitions' as inputs (SKILL.md).
  • Boundary markers: There are no explicit instructions to use delimiters or warnings to ignore instructions embedded within the configuration data.
  • Capability inventory: The skill enables the registration of tools and server connections, which are significant capabilities if configured with malicious intent.
  • Sanitization: The steps do not explicitly include validation, sanitization, or filtering of the provided server and tool specifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 10:49 AM
Security Audit — agent-trust-hub — mcp-server-integration