os-tool-security
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves exclusively as documentation and a security checklist for implementing secure OS tool execution in MCP servers.
- [COMMAND_EXECUTION]: The skill provides code examples demonstrating the difference between insecure (shell=True) and secure (parameterized) command execution. These are educational snippets and do not constitute a security risk.
- [SAFE]: The content explicitly discourages running commands as root and provides implementation details for dropping privileges and using sandboxing mechanisms like containers, seccomp, and AppArmor.
Audit Metadata