fastmcp-creator

Fail

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: CRITICAL
Full Analysis
  • [COMMAND_EXECUTION]: The SKILL.md file contains dynamic context injection markers (!command) used to check the local environment's Python and FastMCP versions. These operations are legitimate developer tool behaviors designed to orient the agent and provide accurate scaffolding advice based on the existing project state.
  • [SAFE]: Automated scanner alerts for https://your-server-url.com are identified as false positives. The URL is used strictly as a placeholder in documentation examples within references/auth.md and references/integrations.md and does not represent a functional or malicious endpoint.
  • [EXTERNAL_DOWNLOADS]: The skill references established packages like anthropic and mcp from PyPI and documentation points to official resources on GitHub and well-known CDNs like unpkg. These dependencies are standard for the Model Context Protocol ecosystem and originate from trusted sources.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 29, 2026, 08:41 AM