MCP Generator
Fail
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The Handlebars template
templates/server.ts.hbsgenerates TypeScript code for an MCP server that usesexecSyncto execute thegitnexusCLI. Arguments for tools likeproject_queryandproject_impactare directly interpolated into a shell command string using double quotes:execSync(`gitnexus query "${args?.query || ""}"`, ...). This implementation is vulnerable to shell injection if the arguments contain shell metacharacters such as backticks, semicolons, or command substitution sequences. - [REMOTE_CODE_EXECUTION]: Because the generated MCP server is intended to be registered with AI clients and executed locally, the command injection vulnerability in the template allows for remote code execution. A malicious prompt or poisoned data processed by the agent could trigger the execution of arbitrary commands on the user's system via the tool interface.
- [DATA_EXFILTRATION]: The instructions in
LITE.mdprovide a template for afetch_api_recordstool that performs outbound network requests usingfetch(endpoint). While it attempts to redactapi_keyparameters using a regular expression, the tool permits the agent to send data to any arbitrary URL provided as input, which can be abused for data exfiltration from the local workspace. - [INDIRECT_PROMPT_INJECTION]: The generated server reads the stdout of the
gitnexusCLI and returns it as plain text to the agent without any sanitization or boundary markers. - Ingestion points:
server.ts.hbs(output ofrunGitnexusfunction). - Boundary markers: None implemented in the generated template.
- Capability inventory: Uses
execSyncfor shell execution and provides file system navigation hints. - Sanitization: None implemented for the external tool output.
Recommendations
- AI detected serious security threats
Audit Metadata