building-mcp-servers

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and fetches documentation from official and trusted sources, including the Model Context Protocol website and official GitHub repositories for the MCP SDKs.
  • [COMMAND_EXECUTION]: The evaluation scripts (scripts/evaluation.py and scripts/connections.py) allow for the execution of local commands and arguments. This functionality is intended to allow developers to launch and test their own MCP servers during the development process.
  • [INDIRECT_PROMPT_INJECTION]: The evaluation harness parses user-provided XML files to extract test questions which are then processed by an LLM. While this presents a surface for indirect prompt injection, it is the primary mechanism for the tool's intended purpose of testing LLM behavior against an MCP server.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — building-mcp-servers