build-custom-mcp-server

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Recommends installing the @modelcontextprotocol/sdk and zod libraries from the official npm registry for Node.js implementations.
  • [EXTERNAL_DOWNLOADS]: Suggests downloading and installing the mcptools package from the Posit (formerly RStudio) official GitHub repository for R-based servers.
  • [COMMAND_EXECUTION]: Instructs the user to use the claude mcp add command to register the newly created server with the local environment, which involves executing shell commands to link the server script.
  • [DATA_EXFILTRATION]: Provides examples of tools designed to query databases and return structured data to the AI assistant. The skill includes a 'Pitfalls' section that explicitly warns users to carefully validate inputs for database queries and shell commands to prevent unauthorized access.
  • [PROMPT_INJECTION]: Contains a vulnerability surface for indirect prompt injection via the query_database and run_analysis tools.
  • Ingestion points: Tool parameters query, analysis_name, and dataset in SKILL.md.
  • Boundary markers: The Node.js example implements a regex check (/^\s*SELECT/i) to ensure only read-only queries are accepted.
  • Capability inventory: The tools utilize DBI::dbGetQuery (R) or executeQuery (Node.js) to access external data sources.
  • Sanitization: While the Node.js example uses regex validation, the R example uses simple string concatenation for the query construction.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 12:14 PM
Security Audit — agent-trust-hub — build-custom-mcp-server