skills/letta-ai/skills/mcp-builder/Gen Agent Trust Hub

mcp-builder

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill represents an indirect prompt injection surface as it is designed to ingest and process external content.\n
  • Ingestion points: The SKILL.md file instructs the agent to fetch external protocol documentation and SDK readmes from modelcontextprotocol.io and GitHub using the WebFetch tool.\n
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the fetched content as untrusted or to ignore any potential instructions embedded within that data.\n
  • Capability inventory: The provided scripts/evaluation.py script has the capability to execute shell commands (via the mcp library's stdio transport) and exposes tools from tested servers to an LLM context.\n
  • Sanitization: The skill does not implement sanitization or validation of the content retrieved from external documentation sources before presenting it to the agent.\n- [COMMAND_EXECUTION]: The scripts/evaluation.py script is designed to execute shell commands provided via command-line arguments to launch and test MCP servers. While this is the intended functionality of the testing harness, it allows for the execution of arbitrary commands in the local environment.\n- [EXTERNAL_DOWNLOADS]: The skill fetches configuration and documentation from the official Model Context Protocol website and GitHub repositories. These sources are well-known repositories for the technology being documented and are considered safe under standard developer workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — mcp-builder