skills/strapi/skills/strapi-docs-mcp/Gen Agent Trust Hub

strapi-docs-mcp

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill retrieves documentation from official Strapi websites (docs.strapi.io) and their public GitHub repository. It also instructs the agent to use a remote MCP server hosted at strapi-docs.mcp.kapa.ai. These sources are recognized as official vendor infrastructure and established documentation search services.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes data from external web pages and documentation sources.
  • Ingestion points: Documentation content from docs.strapi.io, github.com/strapi/documentation, and the strapi-docs tool output.
  • Boundary markers: The skill does not explicitly define delimiters to isolate external documentation content from the agent's instructions.
  • Capability inventory: The agent uses the retrieved information to answer user questions; it does not have associated capabilities like file system writes or arbitrary command execution that could be exploited via documentation content.
  • Sanitization: No specific filtering or sanitization of the retrieved text is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 03:09 PM
Security Audit — agent-trust-hub — strapi-docs-mcp