mcp-builder
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch documentation and SDK README files from the official Model Context Protocol website (modelcontextprotocol.io) and its associated GitHub repository. These are well-known and trusted sources for the protocol being documented.
- [COMMAND_EXECUTION]: The provided
scripts/evaluation.pyscript is designed to execute user-provided shell commands (via the-cand-aflags) to launch local MCP servers for automated testing. This is a standard and necessary function for a development/testing harness. - [REMOTE_CODE_EXECUTION]: While the evaluation script can execute a local server process, it does so based on explicit user input for the purpose of testing a development project. There is no evidence of unauthorized or hidden remote code execution patterns.
- [DATA_EXFILTRATION]: The skill follows security best practices by recommending the use of environment variables (e.g.,
ANTHROPIC_API_KEY) for sensitive credentials rather than hardcoding them. Network operations are limited to communicating with the specified MCP server endpoints and the Anthropic API. - [INDIRECT_PROMPT_INJECTION]: The
evaluation.pyscript implements an agent loop that passes outputs from MCP server tools directly to the LLM. This represents a potential surface for indirect prompt injection if the server returns malicious content, though this is an inherent risk in testing external integrations. - Ingestion points:
scripts/evaluation.py(receives tool result output viaconnection.call_tool). - Boundary markers: None implemented for tool results passed into the message history for the model.
- Capability inventory: The script can invoke any tool exposed by the connected MCP server and interacts with the Anthropic API to process these results.
- Sanitization: Tool outputs are converted to strings or JSON for the message block but are not sanitized for malicious instruction patterns.
Audit Metadata