remote-oauth-mcp-pentest
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a structured set of instructions and templates for conducting authorized security assessments. It establishes clear operating rules, such as requiring explicit scope and authorization before testing, defaulting to read-only operations, and prohibiting the exfiltration of real secrets.
- [COMMAND_EXECUTION]: The skill guides the agent to perform network-based discovery and inventory (e.g., probing .well-known endpoints and MCP transport paths) on user-specified target hosts. This behavior is intrinsic to the skill's stated purpose as a penetration testing tool.
- [INDIRECT_PROMPT_INJECTION]: The skill correctly identifies and instructs the agent to audit for metadata poisoning risks. It specifically warns about unsanitized client metadata (like client_name or logo_uri) being used as a poisoning vector in agent contexts or consent screens, demonstrating a proactive security posture.
Audit Metadata