mcp-builder
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/connections.pyandscripts/evaluation.pyfiles contain logic to execute shell commands provided via CLI arguments. This is the intended mechanism for the evaluation harness to launch and interact with a local MCP server process under test via the standard input/output (stdio) transport. - [EXTERNAL_DOWNLOADS]: The skill instructions in
SKILL.mddirect the agent to fetch documentation from the officialmodelcontextprotocol.iowebsite and official SDK README files from themodelcontextprotocolGitHub organization. These are recognized as trusted and well-known sources for this protocol. - [INDIRECT_PROMPT_INJECTION]: The evaluation harness in
scripts/evaluation.pyingests and processes data returned by MCP server tools to generate reports. This presents a surface for indirect prompt injection if a tool returns malicious instructions intended to influence the evaluation agent. - Ingestion points: Data enters the agent context through
connection.call_toolresults inscripts/evaluation.py. - Boundary markers: The
EVALUATION_PROMPTuses XML tags (<summary>,<feedback>,<response>) to delimit agent output, providing structure that helps mitigate accidental instruction obedience. - Capability inventory: The evaluation script has the capability to call any tool registered by the connected MCP server and communicate with the Anthropic API.
- Sanitization: Tool outputs are converted to strings without specific sanitization before being included in the prompt history for the LLM.
- [CREDENTIALS_UNSAFE]: The documentation in
reference/evaluation.mdandscripts/evaluation.pycorrectly instructs users to manage sensitive credentials likeANTHROPIC_API_KEYorGITHUB_TOKENusing environment variables. This follows security best practices for credential management in development tools.
Audit Metadata