scaffold-mcp
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides architectural patterns and implementation steps for creating MCP servers, serving as a documentation resource rather than an executable script.
- [SAFE]: It explicitly instructs users to implement security measures such as using
execFileinstead ofexecto prevent shell-based command injection and performing strict path validation to mitigate directory traversal risks. - [SAFE]: The external references provided are for educational purposes and point to the author's own domain and relevant GitHub repositories for reference implementations.
Audit Metadata