mcp-integration

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely instructional, providing reference documentation and examples for plugin developers. It does not contain executable code or malicious instructions.
  • [EXTERNAL_DOWNLOADS]: The documentation references official MCP packages such as '@modelcontextprotocol/server-filesystem' via npx, which is the standard method for using these tools.
  • [COMMAND_EXECUTION]: The guidance explains how to configure local MCP servers using standard input/output (stdio) to interact with local processes, which is a core feature of the protocol.
  • [DATA_EXFILTRATION]: The skill actively promotes security best practices by instructing developers to use environment variables for sensitive tokens and avoid hardcoding credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 10:14 PM
Security Audit — agent-trust-hub — mcp-integration