mcp-server-pentest

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a professional security research tool that prioritizes safe testing practices, staging environments, and proper authorization.
  • [COMMAND_EXECUTION]: The instructions reference a local shell script ../../scripts/run-static-checks.sh for initial auditing and suggest using harmless system commands (e.g., whoami, id, pwd) as probes to verify injection vulnerabilities on the target server.
  • [EXTERNAL_DOWNLOADS]: The skill references various playbooks and payload files (e.g., ../../payloads/path-traversal.txt) using relative local paths, which are assumed to be part of the local repository.
  • [PROMPT_INJECTION]: The skill identifies tool descriptions and results as potential attack surfaces for indirect prompt injection and provides a methodology for auditing these risks on the target server.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 04:30 PM
Security Audit — agent-trust-hub — mcp-server-pentest