What problem does it solve?
This Skill solves the critical gap where existing security and compliance frameworks (NIST 800-53, ISO 27001, SOC 2, EU AI Act) have no controls for Model Context Protocol (MCP) trust boundaries, leaving AI coding assistants exposed to local remote code execution, supply chain compromises, and indirect prompt injection attacks via malicious or compromised MCP servers.
Core Features & Use Cases
- MCP Trust Boundary Failure Enumeration: Identifies unaddressed trust gaps including missing tool allowlisting, unsigned server manifests, absent bearer authentication, and zero-interaction RCE vectors.
- Cross-Framework Gap Mapping: Flags where 10+ global compliance frameworks (NIST, ISO, SOC 2, SWIFT CSCF, EU NIS2/DORA, UK CAF, AU Essential 8) fail to cover MCP-specific risks, with explicit control-level gap declarations.
- End-to-End Assessment Workflow: Provides a 5-step procedure to inventory installed MCP servers, verify package provenance, score trust posture, assess CVE exposure (including CVE-2026-30615 and CVE-2026-39884), and generate prioritized remediation actions.
- Defensive Countermeasure Mapping: Aligns findings to D3FEND v1.3.0+ countermeasures for executable allowlisting, payload profiling, and authentication hardening.
- Use Case: A security team using Cursor, Windsurf, or Claude Code can run this skill to audit all developer workstation MCP servers, remove unvetted tools, pin signed versions, and produce a compliance-ready gap report for their annual ISO 27001 audit.
Quick Start
Use the mcp-agent-trust skill to audit all installed MCP servers on your development workstations, flag unvetted tools with RCE or supply chain risk, and generate a compliance gap report for your security audit.