mcp-server-pentest
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a professional security research tool that prioritizes safe testing practices, staging environments, and proper authorization.
- [COMMAND_EXECUTION]: The instructions reference a local shell script
../../scripts/run-static-checks.shfor initial auditing and suggest using harmless system commands (e.g.,whoami,id,pwd) as probes to verify injection vulnerabilities on the target server. - [EXTERNAL_DOWNLOADS]: The skill references various playbooks and payload files (e.g.,
../../payloads/path-traversal.txt) using relative local paths, which are assumed to be part of the local repository. - [PROMPT_INJECTION]: The skill identifies tool descriptions and results as potential attack surfaces for indirect prompt injection and provides a methodology for auditing these risks on the target server.
Audit Metadata