build-mcpb
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- Trusted Vendor Resources: The skill references official schemas and development tools originating from trusted organizations and well-known service repositories. These include the MCPB manifest schema and the Model Context Protocol SDK.
- Security Implementation Guidance: The skill includes a dedicated reference for local security best practices. It provides specific implementation patterns to mitigate common risks such as path traversal and command injection in local tools.
- Input Validation and Sandboxing: The instructions emphasize that tool inputs must be treated as untrusted data. It provides code examples for validating file paths against allowed root directories and using safe execution methods to avoid shell injection.
- Standard Development Workflow: The skill utilizes standard package management and build tools (npm, pip, esbuild) to prepare bundles, following established development practices for local software distribution.
Audit Metadata