mcp-server-builder
Fail
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The TypeScript server implementation in
references/server-implementation.mdcontains a critical command injection vulnerability. In thesearch_codebasetool, thefile_globparameter is directly interpolated into a shell command executed viachild_process.execSync. An agent could pass malicious strings containing shell separators (e.g.,;,&,|) to execute arbitrary commands on the host. - [COMMAND_EXECUTION]: The
run_teststool inreferences/server-implementation.mdis vulnerable to command injection. It constructs a shell command by interpolating thefile_patternvariable into apnpm testcommand string. Without robust escaping of these arguments, an attacker could manipulate the input to perform unauthorized actions. - [DATA_EXFILTRATION]: The skill provides tools and examples that allow for broad data exposure. The
review_codeprompt inreferences/server-implementation.mdusesfs.readFileto read files based on an agent-supplied path. In the absence of path sanitization or restriction to specific directories, an agent could read sensitive configuration files, environment variables, or system files. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its OpenAPI conversion workflow (
scripts/openapi_converter.py). A malicious API specification could be designed to produce tool definitions with deceptive descriptions, tricking the agent into executing dangerous tools or interpreting data incorrectly. - Ingestion points: OpenAPI JSON/YAML specifications are processed by
scripts/openapi_converter.pyandscripts/server_scaffolder.py. - Boundary markers: The generated code and documentation lack boundary markers or explicit instructions for the agent to ignore instructions embedded within the API schema or descriptions.
- Capability inventory: Generated servers possess capabilities for arbitrary command execution (via
execSyncorsubprocess.run) and filesystem access (fsandripgrep). - Sanitization: There is no validation or sanitization of the natural language descriptions or schema metadata imported from external API specifications.
- [CREDENTIALS_UNSAFE]: The documentation in
references/transport-and-deployment.mdprovides configuration examples that include environment variables forDATABASE_URLandAuthorizationheaders. While these are common practices, the skill provides these as copy-paste examples without sufficient warnings about the risks of hardcoding secrets in configuration files likeclaude_desktop_config.json.
Recommendations
- AI detected serious security threats
Audit Metadata