mcp-builder
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches technical documentation and SDK guidelines from official Model Context Protocol (MCP) domains and GitHub repositories to facilitate server development.\n- [COMMAND_EXECUTION]: The evaluation script (
scripts/evaluation.py) programmatically executes local MCP servers as subprocesses via the standard input/output (stdio) transport mechanism to test tool functionality.\n- [DYNAMIC_EXECUTION]: The script uses thesubprocessmodule (via themcpSDK) to launch arbitrary commands and arguments provided through the command-line interface for testing local server implementations.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes input from external evaluation files and dynamic outputs from MCP tools, creating a surface for potential indirect instructions.\n - Ingestion points: Test questions are loaded from user-provided XML files, and the agent processes responses returned by MCP server tools during evaluation cycles.\n
- Boundary markers: The system prompt employs specific XML-style tags (
<summary>,<feedback>,<response>) to delimit agent outputs from external data.\n - Capability inventory: The skill utilizes network access for the Anthropic API and command execution to manage local server processes.\n
- Sanitization: The framework relies on prompt-based structural instructions for the model, without implementing explicit input filtering or sanitization of ingested content.
Audit Metadata