mpp-setup

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation and code samples from trusted and well-known services, including npmjs.com, GitHub, and Stripe. These operations are used to inform the agent's scaffolding logic and do not involve executing untrusted remote code.
  • [COMMAND_EXECUTION]: The skill utilizes standard package managers (npm, pip) to install the project's SDKs and uses openssl for secure local generation of secret keys. These are expected behaviors for a developer-oriented scaffolding tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external websites and search results to guide the project setup. While this creates a potential attack surface, the risk is mitigated by targeting official documentation and reputable platforms.
  • [CREDENTIALS_UNSAFE]: The skill correctly instructs the user to store sensitive keys in environment variables and provides a secure method for generating them locally, avoiding hardcoded secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM