mcp-development

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The review-code prompt template in SKILL.md is susceptible to indirect prompt injection because it interpolates untrusted code diffs directly into the prompt. 1. Ingestion points: diff parameter in review-code prompt template. 2. Boundary markers: Absent. 3. Capability inventory: search_files (globbing) and run_query (SQL). 4. Sanitization: Absent.
  • [COMMAND_EXECUTION]: The run_query tool example uses a weak case-insensitive prefix check for SELECT statements, which can be bypassed to execute unauthorized SQL commands if the template is used in production.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:49 PM
Security Audit — agent-trust-hub — mcp-development