mcp-builder
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The evaluation harness in
scripts/evaluation.pycan execute local commands provided by the user to start MCP servers via the 'stdio' transport. This is a core functionality for testing local server implementations. - [EXTERNAL_DOWNLOADS]: The skill guide recommends fetching documentation from the official Model Context Protocol repositories on GitHub. These are recognized as safe and trusted sources.
- [INDIRECT_PROMPT_INJECTION]: The
scripts/evaluation.pyscript identifies a surface for indirect prompt injection. Ingestion points: Untrusted data enters the context via evaluation XML files and the tool outputs from the server being tested. Boundary markers: The system prompt lacks explicit delimiters to separate this external data from the agent's instructions. Capability inventory: The evaluation agent can call tools on the MCP server, which may perform various actions including network and file operations. Sanitization: External data is not sanitized or escaped before being included in the conversation history.
Audit Metadata