skills/mcp-use/skills/mcp-builder/Gen Agent Trust Hub

mcp-builder

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to bootstrap new projects and setup tunnels using official framework packages via npx (e.g., create-mcp-use-app, @mcp-use/tunnel). These are standard development workflows provided by the vendor.
  • [COMMAND_EXECUTION]: Contains instructions for local development, building, and deployment using standard CLI commands like yarn dev, yarn build, and yarn deploy.
  • [INDIRECT_PROMPT_INJECTION]: As a developer framework, it defines how to build servers that ingest data.
  • Ingestion points: Tools, resources, and prompt definitions in SKILL.md examples.
  • Boundary markers: The documentation explicitly recommends using Zod for strict schema validation on all inputs.
  • Capability inventory: The framework supports tools that can perform arbitrary logic, but provides safe response helpers for output.
  • Sanitization: Recommends using typed response helpers (text, object, markdown) to ensure consistent data structures.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:28 PM
Security Audit — agent-trust-hub — mcp-builder