mcp-builder
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes utility scripts (
scripts/connections.pyandscripts/evaluation.py) designed to launch local MCP servers using thestdiotransport. This allows the tool to execute developer-specified commands as sub-processes, which is standard functionality for local Model Context Protocol integrations. - [EXTERNAL_DOWNLOADS]: The documentation and implementation guides reference and fetch content from official Model Context Protocol GitHub repositories and the official protocol website. These downloads are used to provide the agent and developer with up-to-date SDK information and technical specifications.
- [INDIRECT_PROMPT_INJECTION]: The evaluation script (
scripts/evaluation.py) ingests data from external XML files and tool outputs from MCP servers. This creates a surface where malicious input could influence the agent's behavior during a test run; however, this is a core capability required for its purpose as a test harness and evaluation tool. - Ingestion points:
scripts/evaluation.pyreads test questions from local XML files;scripts/connections.pyretrieves tool lists and results from connected MCP servers. - Boundary markers: The
EVALUATION_PROMPTdefines specific XML-like tags (<summary>,<feedback>,<response>) to help the agent structure its findings and separate its reasoning from the final answer. - Capability inventory: The skill can execute local commands via
stdio, perform network operations via theanthropicSDK, and connect to remote servers via HTTP/SSE. - Sanitization: The tool uses standard XML parsing and JSON serialization, which provides basic structure but does not filter the semantic content of the test questions or tool outputs before they reach the agent.
Audit Metadata