mcp-builder

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The evaluation.py and connections.py scripts facilitate the execution of local programs and scripts through the Model Context Protocol stdio transport. This allows the system to spawn subprocesses based on user-provided command-line arguments to test server implementations. \n- [EXTERNAL_DOWNLOADS]: The skill fetches protocol documentation, SDK guidelines, and specification files from modelcontextprotocol.io and the official Model Context Protocol GitHub repositories. These resources provide the necessary context for building compliant MCP servers. \n- [PROMPT_INJECTION]: The evaluation harness in evaluation.py processes data from external sources within an LLM interaction loop, creating a surface for indirect prompt injection. \n
  • Ingestion points: The script reads data from XML-formatted evaluation files and captures output from MCP tools called during the test cycle. \n
  • Boundary markers: The system prompt (EVALUATION_PROMPT) defines XML tags for the agent to structure its response, although it does not provide explicit instructions to ignore potentially malicious instructions embedded in tool outputs. \n
  • Capability inventory: The script can perform network requests to the Anthropic API and execute local commands through the MCP SDK's transport layer. \n
  • Sanitization: Tool responses are converted to strings before being passed to the model, but the implementation lacks specific sanitization logic to filter or escape command patterns or instructions within the ingested data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 06:18 PM
Security Audit — agent-trust-hub — mcp-builder