mcp-builder

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches technical documentation and SDK guidelines from official Model Context Protocol (MCP) domains and GitHub repositories to facilitate server development.\n- [COMMAND_EXECUTION]: The evaluation script (scripts/evaluation.py) programmatically executes local MCP servers as subprocesses via the standard input/output (stdio) transport mechanism to test tool functionality.\n- [DYNAMIC_EXECUTION]: The script uses the subprocess module (via the mcp SDK) to launch arbitrary commands and arguments provided through the command-line interface for testing local server implementations.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes input from external evaluation files and dynamic outputs from MCP tools, creating a surface for potential indirect instructions.\n
  • Ingestion points: Test questions are loaded from user-provided XML files, and the agent processes responses returned by MCP server tools during evaluation cycles.\n
  • Boundary markers: The system prompt employs specific XML-style tags (<summary>, <feedback>, <response>) to delimit agent outputs from external data.\n
  • Capability inventory: The skill utilizes network access for the Anthropic API and command execution to manage local server processes.\n
  • Sanitization: The framework relies on prompt-based structural instructions for the model, without implementing explicit input filtering or sanitization of ingested content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:00 PM
Security Audit — agent-trust-hub — mcp-builder