review-backport

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructs the user to configure the Phorge MCP server by adding a token to ~/.cursor/mcp.json. It correctly uses the placeholder api-XXXXXXXXXXXXXXXX for the token, adhering to safe secret management practices. All network operations are directed at the vendor's official domain (phorge.dev.yugabyte.com).
  • [EXTERNAL_DOWNLOADS]: The skill requires the @freelancercom/phabricator-mcp package to be run via npx. This is a standard method for loading MCP servers and is necessary for the skill's primary functionality of interacting with the Phorge API.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 04:35 AM
Security Audit — agent-trust-hub — review-backport