hunt-mcp-security

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The documentation contains multiple example bash commands using curl intended for testing server-side vulnerabilities. These examples include payloads for shell command injection (e.g., id, cat /etc/passwd) and SQL injection directed at a hypothetical target domain.
  • [DATA_EXFILTRATION]: Provides instructional examples for verifying data leakage paths, including testing access to sensitive files like /etc/shadow and demonstrating how data might be exfiltrated to external endpoints during a security audit.
  • [PROMPT_INJECTION]: Describes techniques for identifying 'Tool Output Poisoning' and indirect prompt injection, teaching researchers how to test if an agent's behavior can be influenced by malicious responses from external tools.
  • [REMOTE_CODE_EXECUTION]: References a specific vulnerability (CVE-2026-2287) and provides a proof-of-concept JSON payload to demonstrate how arbitrary code could be executed on vulnerable systems via misconfigured MCP servers.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:47 PM
Security Audit — agent-trust-hub — hunt-mcp-security