protect-mcp-governance

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and patterns for agent governance using protect-mcp and Cedar policies. These are legitimate security tools designed for authorization and auditing.
  • [EXTERNAL_DOWNLOADS]: The skill references standard package installations (npx protect-mcp, npx @veritasacta/verify). These are utilities associated with the skill's primary purpose of providing governance and verification for MCP (Model Context Protocol) tool calls.
  • [COMMAND_EXECUTION]: The skill provides examples of shell commands for initializing governance, running servers in shadow/enforce modes, and verifying signed receipts. These commands are descriptive of the tool's intended use and do not contain hidden or dangerous payloads.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents how to author Cedar policies to prevent injection-like behavior (e.g., blocking rm -rf in arguments), serving as a mitigation strategy rather than an attack vector.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 05:24 PM
Security Audit — agent-trust-hub — protect-mcp-governance