test-by-mcpc-cli
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of documentation and instructional content for operating the mcpc CLI. Manual analysis found no evidence of malicious intent, unauthorized data access, or persistence mechanisms.
- [PROMPT_INJECTION]: A static detection for instruction concealment was identified as a false positive. The flagged text describes technical CLI behaviors (such as anonymous testing via
--no-profile) and performance optimization (recommending minimal instruction sets) rather than attempts to hide malicious activity from the user. As the skill is designed to test external servers, it processes untrusted data, which is an inherent risk of the task, but no specific exploitation patterns were found. - [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the mcpc CLI tool from the Apify registry and utilizing official MCP reference servers. These are recognized services and organizations for the intended use case.
- [DATA_EXFILTRATION]: Sensitive file paths used by the mcpc CLI for local storage (e.g.,
~/.mcpc/credentials.json,~/.mcpc/wallets.json) are listed in maintenance and troubleshooting guides. No commands were found that would read and transmit these files to unauthorized external endpoints.
Audit Metadata