uipath-mcp-servers

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the registration of command-type MCP servers via the uip CLI tool, which enables the agent to wrap and execute local shell commands and subprocesses as MCP tools.
  • [EXTERNAL_DOWNLOADS]: The skill provides functionality to connect to external endpoints by allowing the agent to register remote and swagger server types that fetch data from user-specified HTTP URIs or OpenAPI specifications.
  • [DATA_EXFILTRATION]: The skill documentation includes instructions for managing Orchestrator resources and folder-scoped data. It mentions the AssetReferenceSubstitutor mechanism, which handles the runtime resolution of credential-based asset references stored in the Orchestrator platform.
  • [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by ingesting data from external discovery tools and using that content to generate tool metadata and schemas.
  • Ingestion points: Data returned from uip is resources describe and uip agenthub mcp-tools candidates CLI commands as described in references/is-activity-workflow.md.
  • Boundary markers: Absent; there are no instructions to use delimiters or ignore embedded instructions when processing CLI output.
  • Capability inventory: Full shell execution capabilities via the Bash tool and file system modification via Write and Edit tools.
  • Sanitization: Absent; the agent is instructed to compose metadata directly from the CLI's JSON responses without explicit validation or filtering logic mentioned in the prompt instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 01:44 PM
Security Audit — agent-trust-hub — uipath-mcp-servers