mcp-builder

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The evaluation harness in scripts/evaluation.py can execute local commands provided by the user to start MCP servers via the 'stdio' transport. This is a core functionality for testing local server implementations.
  • [EXTERNAL_DOWNLOADS]: The skill guide recommends fetching documentation from the official Model Context Protocol repositories on GitHub. These are recognized as safe and trusted sources.
  • [INDIRECT_PROMPT_INJECTION]: The scripts/evaluation.py script identifies a surface for indirect prompt injection. Ingestion points: Untrusted data enters the context via evaluation XML files and the tool outputs from the server being tested. Boundary markers: The system prompt lacks explicit delimiters to separate this external data from the agent's instructions. Capability inventory: The evaluation agent can call tools on the MCP server, which may perform various actions including network and file operations. Sanitization: External data is not sanitized or escaped before being included in the conversation history.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 11:33 AM