mcp-creator
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a local utility script
scripts/check_mcp_conformance.pyand provides explicit instructions for the agent to execute it using the Python interpreter to analyze server source code. - [INDIRECT_PROMPT_INJECTION]: The conformance checker script performs static analysis on external files provided by the user, creating a surface where malicious instructions embedded in the analyzed code could potentially influence the agent's subsequent review of the findings.
- Ingestion points: The script reads file content from a user-specified directory via
scripts/check_mcp_conformance.py. - Boundary markers: None identified in the script's reporting output.
- Capability inventory: The script is limited to file system read access for analysis purposes; it contains no file-write, network, or privileged execution capabilities.
- Sanitization: None; the script performs raw text analysis using regular expressions.
Audit Metadata