suvvy-mcp
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions and shell command templates for using
curlto upload files to presigned URLs and download remote files to a temporary directory before importing them into the Suvvy platform (referenced inreferences/uploading-files.md). - [EXTERNAL_DOWNLOADS]: Includes capabilities for fetching and parsing external web pages through a
scrape_urltool and downloading files from user-provided URLs to populate the platform's knowledge base. - [DATA_EXFILTRATION]: Supports the creation of webhooks and external API calls within Custom Tools, allowing data transfer between the Suvvy platform and third-party services as a core feature for platform integration.
- [PROMPT_INJECTION]: The skill manages surfaces for indirect prompt injection. 1. Ingestion points: Big Documents and scraped URLs (references/kb-big-documents.md, references/custom-tools.md). 2. Boundary markers: Not specified in the instructions for these ingestion points. 3. Capability inventory: Webhooks, bot calls, SQL queries, and memory settings. 4. Sanitization: No explicit sanitization or filtering logic is provided for external data processing. Additionally, it describes 'Decoy FAQ Documents' to manage bot hallucinations and the use of Liquid templates for dynamic prompt generation.
Audit Metadata