agents-mcp

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing and running various MCP servers using the npx package runner. These include official packages under the @modelcontextprotocol scope, well-known database tools like dbhub, and community-maintained research tools such as exa-mcp-server and firecrawl-mcp. These references are standard for the MCP ecosystem and target established tools.
  • [COMMAND_EXECUTION]: The skill includes TypeScript and Python templates for building custom MCP servers that execute commands on databases (PostgreSQL/MySQL), filesystems, and remote APIs. It incorporates robust security guidance for these operations, emphasizing the use of parameterized queries, strict schema validation, and path normalization to prevent injection attacks.
  • [INDIRECT_PROMPT_INJECTION]: The documentation explicitly addresses the risks of indirect prompt injection where untrusted data (e.g., from external web searches or issue trackers) is processed by the agent. It provides detailed remediation strategies, including the use of structured output schemas, isolation of untrusted fields, and implementing human-in-the-loop approval for all state-changing operations.
  • [DATA_EXFILTRATION]: The skill provides high-leverage security patterns for protecting sensitive data, specifically for data warehouse integrations. This includes mandatory read-only database roles, row-level security (RLS), column-level security (CLS), and the enforcement of query budgets (timeouts and row limits) to prevent unauthorized large-scale data harvesting.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — agents-mcp