mcp-builder
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The evaluation script
scripts/evaluation.pyand connection utilityscripts/connections.pyenable the execution of local shell commands and arguments. This is the intended mechanism for starting and interacting with local MCP servers for testing purposes.- [EXTERNAL_DOWNLOADS]: The skill instructions advise fetching documentation and resource files from the officialmodelcontextprotocol.iowebsite and associated GitHub repositories.- [INDIRECT_PROMPT_INJECTION]: The evaluation harness parses questions from XML files and includes them in model prompts without sanitization, creating an attack surface for untrusted content.\n - Ingestion points: Data is ingested through the
parse_evaluation_filefunction from a user-provided XML file path.\n - Boundary markers: The questions are incorporated into the dialogue history without specific boundary delimiters or instructions to ignore embedded commands.\n
- Capability inventory: The script is capable of executing local commands (via stdio), interacting with MCP tools, and communicating with the Anthropic API.\n
- Sanitization: No validation or sanitization is performed on the question text before it is sent to the LLM.
Audit Metadata