OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Warn3 providerslatest audit Sep 4, 2026
Independent checks from skills.sh's audit partners.
The skill facilitates the integration of Model Context Protocol (MCP) servers into an AI agent's environment. While legitimate, it creates an attack surface for indirect prompt injection from third-party server outputs and documents a default storage configuration that persists sensitive tokens in plain text within the browser's local storage.
Detected behaviors
No alerts
1 issue