skills/saschb2b/skills/scaffold-mcp/Gen Agent Trust Hub

scaffold-mcp

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides architectural patterns and implementation steps for creating MCP servers, serving as a documentation resource rather than an executable script.
  • [SAFE]: It explicitly instructs users to implement security measures such as using execFile instead of exec to prevent shell-based command injection and performing strict path validation to mitigate directory traversal risks.
  • [SAFE]: The external references provided are for educational purposes and point to the author's own domain and relevant GitHub repositories for reference implementations.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 03:00 PM
Security Audit — agent-trust-hub — scaffold-mcp