factory-mcp
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill contains only documentation and instructions for using an external MCP server, without any standalone executable code.
- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes data from external sources like Slack and Linear. 1. Ingestion points: The skill description mentions finding work from Slack threads and Linear tickets. 2. Boundary markers: No explicit delimiters or isolation warnings are provided in the current instructions. 3. Capability inventory: The skill leverages MCP tools to bundle local files and synchronize work with cloud environments. 4. Sanitization: No explicit filtering or sanitization of external content is described.
Audit Metadata