stigg-mcp
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill serves as a configuration guide for the Stigg environment. All listed domains (stigg.io, mcp.stigg.io, app.stigg.io) and GitHub repositories (github.com/stiggio/stigg-cli) are verified vendor-owned resources used for legitimate authentication and service interaction.
- [EXTERNAL_DOWNLOADS]: The instructions describe installing the Stigg CLI via official channels (Homebrew or Go) and running the '@stigg/typescript-mcp' package via npx. These are standard and expected procedures for deploying the vendor's integration tools.
- [CREDENTIALS_UNSAFE]: The documentation mentions the use of API keys but correctly uses placeholders (e.g., '<YOUR_API_KEY>') and provides explicit security advice to users about treating keys like passwords and avoiding committing them to version control.
Audit Metadata