mcp-sentinel

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Automated scan findings for remote code execution patterns refer to strings within the tests/test_hook.py file. These are used as negative test cases to ensure the security hook can effectively block unauthorized shell pipes.
  • [DATA_EXFILTRATION]: Known-malicious domains like giftshop.club and various pastebin services are included in the skill's indicator of compromise (IOC) library. These serve as defensive signatures to prevent data theft rather than facilitate it.
  • [PROMPT_INJECTION]: The skill instructions and IOC database contain lists of common prompt injection phrases. These are utilized as detection patterns for the security agent to identify potential risks in other installed skills.
  • [COMMAND_EXECUTION]: Shell command execution within the project is limited to installation and uninstallation scripts and the execution of the local Python security hook for testing purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 09:51 AM
Security Audit — agent-trust-hub — mcp-sentinel