mcp-integration

Pass

Audited by Gen Agent Trust Hub on Mar 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of documentation, examples, and reference material intended to guide developers in implementing MCP integration. No malicious code or instructions were found.
  • [COMMAND_EXECUTION]: The documentation describes the use of the stdio transport for running local MCP servers. Examples demonstrate legitimate use of npx and python to launch server processes, with a strong recommendation to use ${CLAUDE_PLUGIN_ROOT} for portable and predictable file paths.
  • [EXTERNAL_DOWNLOADS]: Examples illustrate connecting to well-known hosted services like Asana and GitHub using secure SSE and HTTPS transports.
  • [SAFE]: The documentation provides detailed guidance on authentication, explicitly warning against hardcoding credentials and instructing users to manage secrets through environment variables or OAuth flows, adhering to security best practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 24, 2026, 12:47 AM