mcp-builder
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill represents an indirect prompt injection surface as it is designed to ingest and process external content.\n
- Ingestion points: The
SKILL.mdfile instructs the agent to fetch external protocol documentation and SDK readmes frommodelcontextprotocol.ioand GitHub using theWebFetchtool.\n - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the fetched content as untrusted or to ignore any potential instructions embedded within that data.\n
- Capability inventory: The provided
scripts/evaluation.pyscript has the capability to execute shell commands (via themcplibrary's stdio transport) and exposes tools from tested servers to an LLM context.\n - Sanitization: The skill does not implement sanitization or validation of the content retrieved from external documentation sources before presenting it to the agent.\n- [COMMAND_EXECUTION]: The
scripts/evaluation.pyscript is designed to execute shell commands provided via command-line arguments to launch and test MCP servers. While this is the intended functionality of the testing harness, it allows for the execution of arbitrary commands in the local environment.\n- [EXTERNAL_DOWNLOADS]: The skill fetches configuration and documentation from the official Model Context Protocol website and GitHub repositories. These sources are well-known repositories for the technology being documented and are considered safe under standard developer workflows.
Audit Metadata