add-mcp-oauth

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a legitimate technical workflow for adding OAuth 2.1 authentication to MCP servers using official Scalekit SDKs.\n- [CREDENTIALS_UNSAFE]: No hardcoded credentials or secrets were found; the skill correctly instructs the user to store sensitive API credentials in environment variables.\n- [EXTERNAL_DOWNLOADS]: Package dependencies are restricted to standard, well-known libraries (e.g., express, fastapi, scalekit-sdk) sourced from official registries.\n- [REMOTE_CODE_EXECUTION]: No patterns for remote code execution, dynamic shell script downloading, or unauthorized command execution were detected.\n- [PROMPT_INJECTION]: The instructions are strictly technical and do not contain patterns aimed at overriding agent behavior or bypassing safety guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 02:20 PM
Security Audit — agent-trust-hub — add-mcp-oauth