hunt-mcp-security
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The documentation contains multiple example bash commands using
curlintended for testing server-side vulnerabilities. These examples include payloads for shell command injection (e.g.,id,cat /etc/passwd) and SQL injection directed at a hypothetical target domain. - [DATA_EXFILTRATION]: Provides instructional examples for verifying data leakage paths, including testing access to sensitive files like
/etc/shadowand demonstrating how data might be exfiltrated to external endpoints during a security audit. - [PROMPT_INJECTION]: Describes techniques for identifying 'Tool Output Poisoning' and indirect prompt injection, teaching researchers how to test if an agent's behavior can be influenced by malicious responses from external tools.
- [REMOTE_CODE_EXECUTION]: References a specific vulnerability (CVE-2026-2287) and provides a proof-of-concept JSON payload to demonstrate how arbitrary code could be executed on vulnerable systems via misconfigured MCP servers.
Audit Metadata