mcp-builder
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/evaluation.pyandscripts/connections.pyallow developers to run local MCP servers for testing purposes. They utilize themcplibrary to manage subprocesses via standard input/output (stdio). This behavior is a core functional requirement for a developer evaluation harness and is limited to local execution. - [EXTERNAL_DOWNLOADS]: The skill provides references to official protocol documentation and SDKs hosted on
modelcontextprotocol.ioand GitHub. These are well-known and trusted sources for developers working with the Model Context Protocol. - [SAFE]: The skill provides explicit security recommendations for developers, such as implementing DNS rebinding protection and using environment variables for sensitive API keys. No signs of obfuscation, data exfiltration, or malicious persistence were detected.
Audit Metadata