mcp-audit
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill accesses sensitive configuration files
~/.claude/settings.jsonand.claude/settings.json. These files store the environment and authentication parameters for MCP servers, which frequently include secrets like API tokens and credentials in theirenvblocks. The commandgrep -A 50 "mcpServers"extracts and displays these configurations, leading to the exposure of credentials within the agent's context and output history.\n- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (catandgrep) to programmatically read and filter local application configuration files.
Audit Metadata