mcp-sync
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill manages the synchronization of MCP server configurations between Claude Code, opencode, and Codex agents using a local markdown file as the source of truth.- [SAFE]: It contains rigorous instructions to strip sensitive data such as API keys, tokens, or authentication headers from configuration files to prevent credential exposure in shared repositories.- [SAFE]: The workflow mandates human-in-the-loop confirmation for adding, modifying, or removing servers, which prevents the agent from making autonomous or unauthorized changes to the project's environment.- [SAFE]: Although the skill processes untrusted input from project configuration files (Indirect Prompt Injection surface), it mitigates this risk by requiring manual review of connection details and providing strict rendering rules.- [SAFE]: No suspicious patterns such as obfuscation, persistence mechanisms, privilege escalation, or unauthorized network exfiltration were detected in the skill instructions or referenced dialects.
Audit Metadata