alchemy-mcp
Pass
Audited by Gen Agent Trust Hub on Apr 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructions for connecting AI clients to the official Alchemy MCP server at https://mcp.alchemy.com/mcp. This is a standard integration pattern for the Model Context Protocol.
- [SAFE]: Authentication is handled via the OAuth 2.1 protocol with PKCE. This is a secure authentication method that allows the agent to function without requiring the user to share or the agent to store raw API keys.
- [SAFE]: All external URLs and GitHub repository references point to the verified infrastructure of the author, alchemyplatform.
- [SAFE]: No malicious patterns such as prompt injection, obfuscation, or unauthorized command execution were detected.
- [SAFE]: While the skill retrieves blockchain data (which constitutes an indirect prompt injection surface), it does not possess dangerous capabilities like shell execution or arbitrary file writes that could be leveraged by malicious data content.
Audit Metadata