mcp-audit

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses sensitive configuration files ~/.claude/settings.json and .claude/settings.json. These files store the environment and authentication parameters for MCP servers, which frequently include secrets like API tokens and credentials in their env blocks. The command grep -A 50 "mcpServers" extracts and displays these configurations, leading to the exposure of credentials within the agent's context and output history.\n- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (cat and grep) to programmatically read and filter local application configuration files.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:50 PM
Security Audit — agent-trust-hub — mcp-audit