mcp-best-practices

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a static documentation resource for MCP best practices and does not include executable code or instructions that bypass safety guardrails.
  • [SAFE]: The potentially dangerous command patterns identified by static scanners (such as curl POSTing sensitive files or sudo commands) are explicitly used within the references/security-auth.md file as illustrative examples of malicious attacks that developers should mitigate against. These are clearly labeled for educational purposes and are not intended for agent execution.
  • [SAFE]: All external URL references target official documentation (modelcontextprotocol.io), trusted development platforms (GitHub), or well-known technology vendors. Placeholder domains like evil.com or example.com are used correctly within documentation examples.
  • [SAFE]: The skill implements best practices for its own metadata and instructions, providing clear versioning, upstream dependencies, and environment variable descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 03:36 PM
Security Audit — agent-trust-hub — mcp-best-practices