fastmcp-creator
Fail
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: CRITICAL
Full Analysis
- [COMMAND_EXECUTION]: The SKILL.md file contains dynamic context injection markers (!
command) used to check the local environment's Python and FastMCP versions. These operations are legitimate developer tool behaviors designed to orient the agent and provide accurate scaffolding advice based on the existing project state. - [SAFE]: Automated scanner alerts for
https://your-server-url.comare identified as false positives. The URL is used strictly as a placeholder in documentation examples withinreferences/auth.mdandreferences/integrations.mdand does not represent a functional or malicious endpoint. - [EXTERNAL_DOWNLOADS]: The skill references established packages like
anthropicandmcpfrom PyPI and documentation points to official resources on GitHub and well-known CDNs like unpkg. These dependencies are standard for the Model Context Protocol ecosystem and originate from trusted sources.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata