strapi-docs-mcp
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill retrieves documentation from official Strapi websites (
docs.strapi.io) and their public GitHub repository. It also instructs the agent to use a remote MCP server hosted atstrapi-docs.mcp.kapa.ai. These sources are recognized as official vendor infrastructure and established documentation search services. - [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes data from external web pages and documentation sources.
- Ingestion points: Documentation content from
docs.strapi.io,github.com/strapi/documentation, and thestrapi-docstool output. - Boundary markers: The skill does not explicitly define delimiters to isolate external documentation content from the agent's instructions.
- Capability inventory: The agent uses the retrieved information to answer user questions; it does not have associated capabilities like file system writes or arbitrary command execution that could be exploited via documentation content.
- Sanitization: No specific filtering or sanitization of the retrieved text is described.
Audit Metadata