mcp-builder
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/evaluation.pyandscripts/connections.pyscripts facilitate the execution of shell commands through the Model Context Protocol'sstdiotransport mechanism. This is an intended feature for launching and interacting with MCP servers during development and testing. - [EXTERNAL_DOWNLOADS]: The documentation in
SKILL.mddirects the agent to fetch protocol specifications and SDK README files from well-known sources, including themodelcontextprotocol.iodomain and themodelcontextprotocolorganization's official GitHub repositories. - [INDIRECT_PROMPT_INJECTION]: The evaluation harness processes external data which presents a theoretical attack surface.
- Ingestion points: The
scripts/evaluation.pyscript reads evaluation tasks from XML files and processes output returned by tools during the agent loop. - Capability inventory: The harness can execute shell commands, make network calls, and interact with the Anthropic API.
- Boundary markers: The
EVALUATION_PROMPTuses structured XML-style tags to help the model distinguish between summary, feedback, and final response content. - Sanitization: The harness does not implement specific sanitization for the evaluation questions or tool outputs before they are processed by the agent.
- [DYNAMIC_EXECUTION]: The skill enables the dynamic execution of local server implementations through command-line interaction, allowing the agent to launch and test binaries or scripts designated as MCP servers.
Audit Metadata