mcp-builder

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references official Model Context Protocol documentation at modelcontextprotocol.io and the official Python SDK repository on GitHub. These are well-known, trusted sources for this specific technology.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides templates for building tools that take string inputs (e.g., search queries). This is a standard functional requirement for MCP servers. The skill mitigates risks by recommending strict data validation using Pydantic models for complex inputs.
  • [COMMAND_EXECUTION]: The skill instructions include standard development commands using uv and npx to initialize projects and test servers. These commands are intended for the developer's local environment and target official project tooling.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:53 PM
Security Audit — agent-trust-hub — mcp-builder