MCP Integration
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely composed of markdown documentation and JSON configuration examples for educational purposes. No executable scripts are included in the package.
- [EXTERNAL_DOWNLOADS]: Documentation suggests the use of official Model Context Protocol packages (such as @modelcontextprotocol/server-filesystem) from the npm registry, which is a well-known and expected service for this protocol.
- [COMMAND_EXECUTION]: Describes patterns for configuring stdio MCP servers and helper scripts for dynamic header generation, providing clear guidance on using absolute paths and environment variables to ensure secure execution.
- [CREDENTIALS_UNSAFE]: Specifically highlights security best practices by instructing developers to use environment variables for secrets and leverage OAuth flows instead of hardcoding sensitive credentials.
Audit Metadata