mcp-builder

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/evaluation.py and scripts/connections.py allow developers to run local MCP servers for testing purposes. They utilize the mcp library to manage subprocesses via standard input/output (stdio). This behavior is a core functional requirement for a developer evaluation harness and is limited to local execution.
  • [EXTERNAL_DOWNLOADS]: The skill provides references to official protocol documentation and SDKs hosted on modelcontextprotocol.io and GitHub. These are well-known and trusted sources for developers working with the Model Context Protocol.
  • [SAFE]: The skill provides explicit security recommendations for developers, such as implementing DNS rebinding protection and using environment variables for sensitive API keys. No signs of obfuscation, data exfiltration, or malicious persistence were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:46 AM
Security Audit — agent-trust-hub — mcp-builder