mcp-server-builder

Fail

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The TypeScript server implementation in references/server-implementation.md contains a critical command injection vulnerability. In the search_codebase tool, the file_glob parameter is directly interpolated into a shell command executed via child_process.execSync. An agent could pass malicious strings containing shell separators (e.g., ;, &, |) to execute arbitrary commands on the host.
  • [COMMAND_EXECUTION]: The run_tests tool in references/server-implementation.md is vulnerable to command injection. It constructs a shell command by interpolating the file_pattern variable into a pnpm test command string. Without robust escaping of these arguments, an attacker could manipulate the input to perform unauthorized actions.
  • [DATA_EXFILTRATION]: The skill provides tools and examples that allow for broad data exposure. The review_code prompt in references/server-implementation.md uses fs.readFile to read files based on an agent-supplied path. In the absence of path sanitization or restriction to specific directories, an agent could read sensitive configuration files, environment variables, or system files.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its OpenAPI conversion workflow (scripts/openapi_converter.py). A malicious API specification could be designed to produce tool definitions with deceptive descriptions, tricking the agent into executing dangerous tools or interpreting data incorrectly.
  • Ingestion points: OpenAPI JSON/YAML specifications are processed by scripts/openapi_converter.py and scripts/server_scaffolder.py.
  • Boundary markers: The generated code and documentation lack boundary markers or explicit instructions for the agent to ignore instructions embedded within the API schema or descriptions.
  • Capability inventory: Generated servers possess capabilities for arbitrary command execution (via execSync or subprocess.run) and filesystem access (fs and ripgrep).
  • Sanitization: There is no validation or sanitization of the natural language descriptions or schema metadata imported from external API specifications.
  • [CREDENTIALS_UNSAFE]: The documentation in references/transport-and-deployment.md provides configuration examples that include environment variables for DATABASE_URL and Authorization headers. While these are common practices, the skill provides these as copy-paste examples without sufficient warnings about the risks of hardcoding secrets in configuration files like claude_desktop_config.json.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 19, 2026, 02:16 AM
Security Audit — agent-trust-hub — mcp-server-builder