mcp-chaining

Warn

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill builds a multi-step pipeline that retrieves data from external documentation searches (nia__search) and structural codebase searches (ast-grep, morph). This design creates a vulnerability to indirect prompt injection, where malicious instructions hidden in the documentation or code being searched could be interpreted as commands by the agent in later stages. * Ingestion points: Data entering the pipeline from the nia__search, ast-grep__find_code, and morph__warpgrep_codebase_search tools referenced in SKILL.md. * Boundary markers: The instructions do not define delimiters or specific 'ignore' rules to distinguish between data and instructions when processing these tool outputs. * Capability inventory: The skill is configured with Bash and Read capabilities, allowing an attacker to potentially execute commands or read files if they successfully inject instructions into the pipeline data. * Sanitization: There is no evidence of sanitization, filtering, or validation logic applied to the outputs of the research tools before they are used to drive implementation steps.
  • [CREDENTIALS_UNSAFE]: The skill explicitly advises users to modify their mcp_client.py runtime to pass the full host environment (os.environ) to subprocesses. While this is intended to ensure specific API keys are available to tools, this practice exposes all environment-stored secrets—such as AWS credentials, database connection strings, and private tokens—to every tool executed by the agent, violating the principle of least privilege.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — mcp-chaining