migrate-strapi-content

Warn

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The 'iteration-log.md' file (Tick 1) instructs the agent to access local filesystem credentials at '~/.mcp/strapi-mcp-server.config.json' to retrieve authentication tokens for API interactions when platform tools fail.
  • [PROMPT_INJECTION]: The 'SKILL.md' file establishes a 'Hard rule: NEVER ask the user anything — no exceptions', which is a directive to bypass standard human-in-the-loop safety protocols and confirmation steps before performing destructive 'replace' operations on production content.
  • [COMMAND_EXECUTION]: The skill uses 'mcp__plugin_playwright_playwright__browser_evaluate' to execute custom JavaScript snippets for analyzing rendered DOM structures and calculating coordinates for screenshots.
  • [DYNAMIC_EXECUTION]: The 'perfection-loop.md' documents a self-modifying logic where the AI agent is authorized to autonomously edit the skill's own instruction files (SKILL.md and components-cheatsheet.csv) to refine its behavior based on previous execution outcomes.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 21, 2026, 08:49 PM
Security Audit — agent-trust-hub — migrate-strapi-content