uipath-mcp-servers
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the registration of
command-type MCP servers via theuipCLI tool, which enables the agent to wrap and execute local shell commands and subprocesses as MCP tools. - [EXTERNAL_DOWNLOADS]: The skill provides functionality to connect to external endpoints by allowing the agent to register
remoteandswaggerserver types that fetch data from user-specified HTTP URIs or OpenAPI specifications. - [DATA_EXFILTRATION]: The skill documentation includes instructions for managing Orchestrator resources and folder-scoped data. It mentions the
AssetReferenceSubstitutormechanism, which handles the runtime resolution of credential-based asset references stored in the Orchestrator platform. - [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by ingesting data from external discovery tools and using that content to generate tool metadata and schemas.
- Ingestion points: Data returned from
uip is resources describeanduip agenthub mcp-tools candidatesCLI commands as described inreferences/is-activity-workflow.md. - Boundary markers: Absent; there are no instructions to use delimiters or ignore embedded instructions when processing CLI output.
- Capability inventory: Full shell execution capabilities via the
Bashtool and file system modification viaWriteandEdittools. - Sanitization: Absent; the agent is instructed to compose metadata directly from the CLI's JSON responses without explicit validation or filtering logic mentioned in the prompt instructions.
Audit Metadata