build-mcp-app

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends the use of official Model Context Protocol packages, specifically @modelcontextprotocol/sdk and @modelcontextprotocol/ext-apps, which are standard for this ecosystem.
  • [COMMAND_EXECUTION]: Boilerplate examples include running a local development server using express and utilizing Node.js file system APIs to manage and serve local widget assets.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were detected. The skill provides instructions on how to bundle local SDK assets into HTML resources to satisfy strict sandbox environments, rather than fetching external scripts at runtime.
  • [DATA_EXFILTRATION]: Outbound communications from within the UI widgets (such as opening links or downloading files) are mediated by the host via the provided SDK API, ensuring these actions are visible and restricted to authorized channels.
  • [PROMPT_INJECTION]: The content is focused entirely on technical implementation and architectural guidance for developers, with no instructions observed that attempt to bypass or override AI agent safety protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — build-mcp-app