mcp-server-offering

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely instructional and does not include any executable code, scripts, or dynamic context injection. It focuses on providing architectural and strategic guidance for developers.
  • [SAFE]: All external references to third-party services (e.g., Stripe, Sentry, Cloudflare) are used as legitimate examples of industry best practices and do not involve unauthorized data access or exfiltration.
  • [SAFE]: The skill does not employ any form of obfuscation, persistent access mechanisms, or credential harvesting. It encourages the use of secure protocols like OAuth 2.1 and scoped credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection by ingesting user-provided API requirements. However, this surface is considered safe due to the absence of exploitable capabilities.
  • Ingestion points: User-supplied API context and design requirements (SKILL.md).
  • Boundary markers: Absent.
  • Capability inventory: No executable capabilities, tools, or scripts are provided in any of the skill's files.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:17 PM
Security Audit — agent-trust-hub — mcp-server-offering