mcp-builder
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references official Model Context Protocol documentation at
modelcontextprotocol.ioand the official Python SDK repository on GitHub. These are well-known, trusted sources for this specific technology. - [INDIRECT_PROMPT_INJECTION]: The skill provides templates for building tools that take string inputs (e.g., search queries). This is a standard functional requirement for MCP servers. The skill mitigates risks by recommending strict data validation using Pydantic models for complex inputs.
- [COMMAND_EXECUTION]: The skill instructions include standard development commands using
uvandnpxto initialize projects and test servers. These commands are intended for the developer's local environment and target official project tooling.
Audit Metadata