mcp-creator

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references official Model Context Protocol (MCP) tooling and software development kits (e.g., @modelcontextprotocol/sdk, @modelcontextprotocol/inspector) to be installed via standard package managers. These resources originate from established and well-known service providers.\n- [COMMAND_EXECUTION]: The provided templates and reference documentation include patterns for executing shell commands and database operations. These are presented with a strong emphasis on security best practices, such as using execFile with argument arrays to prevent command injection and parameterized queries to mitigate SQL injection.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of MCP servers that ingest external data, creating a potential indirect prompt injection surface. The skill mitigates this risk by documenting a mandatory evidence chain for security:\n
  • Ingestion points: Tool handlers in the provided templates receive untrusted arguments in templates/authenticated-api.ts and templates/basic-server.ts.\n
  • Boundary markers: The documentation and templates enforce the use of strict Zod schemas to define tool inputs and validate them at the entry point.\n
  • Capability inventory: Detailed patterns for network requests, database access, and system command execution are documented across the reference files.\n
  • Sanitization: The skill provides robust examples of input validation (schema.parse()), escaping, and parameterized operations to ensure external content is handled safely.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — mcp-creator