mcp-chaining
Warn
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill builds a multi-step pipeline that retrieves data from external documentation searches (nia__search) and structural codebase searches (ast-grep, morph). This design creates a vulnerability to indirect prompt injection, where malicious instructions hidden in the documentation or code being searched could be interpreted as commands by the agent in later stages. * Ingestion points: Data entering the pipeline from the nia__search, ast-grep__find_code, and morph__warpgrep_codebase_search tools referenced in SKILL.md. * Boundary markers: The instructions do not define delimiters or specific 'ignore' rules to distinguish between data and instructions when processing these tool outputs. * Capability inventory: The skill is configured with Bash and Read capabilities, allowing an attacker to potentially execute commands or read files if they successfully inject instructions into the pipeline data. * Sanitization: There is no evidence of sanitization, filtering, or validation logic applied to the outputs of the research tools before they are used to drive implementation steps.
- [CREDENTIALS_UNSAFE]: The skill explicitly advises users to modify their mcp_client.py runtime to pass the full host environment (os.environ) to subprocesses. While this is intended to ensure specific API keys are available to tools, this practice exposes all environment-stored secrets—such as AWS credentials, database connection strings, and private tokens—to every tool executed by the agent, violating the principle of least privilege.
Audit Metadata