protect-mcp-governance
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and patterns for agent governance using
protect-mcpandCedarpolicies. These are legitimate security tools designed for authorization and auditing. - [EXTERNAL_DOWNLOADS]: The skill references standard package installations (
npx protect-mcp,npx @veritasacta/verify). These are utilities associated with the skill's primary purpose of providing governance and verification for MCP (Model Context Protocol) tool calls. - [COMMAND_EXECUTION]: The skill provides examples of shell commands for initializing governance, running servers in shadow/enforce modes, and verifying signed receipts. These commands are descriptive of the tool's intended use and do not contain hidden or dangerous payloads.
- [INDIRECT_PROMPT_INJECTION]: The skill documents how to author Cedar policies to prevent injection-like behavior (e.g., blocking
rm -rfin arguments), serving as a mitigation strategy rather than an attack vector.
Audit Metadata