skills/zackbart/skills/mcp-sync/Gen Agent Trust Hub

mcp-sync

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill manages the synchronization of MCP server configurations between Claude Code, opencode, and Codex agents using a local markdown file as the source of truth.- [SAFE]: It contains rigorous instructions to strip sensitive data such as API keys, tokens, or authentication headers from configuration files to prevent credential exposure in shared repositories.- [SAFE]: The workflow mandates human-in-the-loop confirmation for adding, modifying, or removing servers, which prevents the agent from making autonomous or unauthorized changes to the project's environment.- [SAFE]: Although the skill processes untrusted input from project configuration files (Indirect Prompt Injection surface), it mitigates this risk by requiring manual review of connection details and providing strict rendering rules.- [SAFE]: No suspicious patterns such as obfuscation, persistence mechanisms, privilege escalation, or unauthorized network exfiltration were detected in the skill instructions or referenced dialects.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 02:26 AM
Security Audit — agent-trust-hub — mcp-sync