mcp-builder

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The evaluation script scripts/evaluation.py and connection utility scripts/connections.py enable the execution of local shell commands and arguments. This is the intended mechanism for starting and interacting with local MCP servers for testing purposes.- [EXTERNAL_DOWNLOADS]: The skill instructions advise fetching documentation and resource files from the official modelcontextprotocol.io website and associated GitHub repositories.- [INDIRECT_PROMPT_INJECTION]: The evaluation harness parses questions from XML files and includes them in model prompts without sanitization, creating an attack surface for untrusted content.\n
  • Ingestion points: Data is ingested through the parse_evaluation_file function from a user-provided XML file path.\n
  • Boundary markers: The questions are incorporated into the dialogue history without specific boundary delimiters or instructions to ignore embedded commands.\n
  • Capability inventory: The script is capable of executing local commands (via stdio), interacting with MCP tools, and communicating with the Anthropic API.\n
  • Sanitization: No validation or sanitization is performed on the question text before it is sent to the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — mcp-builder