migrate-strapi-content
Warn
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The 'iteration-log.md' file (Tick 1) instructs the agent to access local filesystem credentials at '~/.mcp/strapi-mcp-server.config.json' to retrieve authentication tokens for API interactions when platform tools fail.
- [PROMPT_INJECTION]: The 'SKILL.md' file establishes a 'Hard rule: NEVER ask the user anything — no exceptions', which is a directive to bypass standard human-in-the-loop safety protocols and confirmation steps before performing destructive 'replace' operations on production content.
- [COMMAND_EXECUTION]: The skill uses 'mcp__plugin_playwright_playwright__browser_evaluate' to execute custom JavaScript snippets for analyzing rendered DOM structures and calculating coordinates for screenshots.
- [DYNAMIC_EXECUTION]: The 'perfection-loop.md' documents a self-modifying logic where the AI agent is authorized to autonomously edit the skill's own instruction files (SKILL.md and components-cheatsheet.csv) to refine its behavior based on previous execution outcomes.
Audit Metadata