add-mcp-oauth
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a legitimate technical workflow for adding OAuth 2.1 authentication to MCP servers using official Scalekit SDKs.\n- [CREDENTIALS_UNSAFE]: No hardcoded credentials or secrets were found; the skill correctly instructs the user to store sensitive API credentials in environment variables.\n- [EXTERNAL_DOWNLOADS]: Package dependencies are restricted to standard, well-known libraries (e.g., express, fastapi, scalekit-sdk) sourced from official registries.\n- [REMOTE_CODE_EXECUTION]: No patterns for remote code execution, dynamic shell script downloading, or unauthorized command execution were detected.\n- [PROMPT_INJECTION]: The instructions are strictly technical and do not contain patterns aimed at overriding agent behavior or bypassing safety guidelines.
Audit Metadata