build-mcp-server

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents best practices for MCP server development, including structured discovery phases and clear decision matrices for deployment models.
  • [SAFE]: Authentication guidance correctly emphasizes using the OS keychain for local token storage and promotes standard OAuth flows (CIMD/DCR) for remote servers, explicitly forbidding insecure practices like plaintext storage or token passthrough.
  • [SAFE]: Scaffolding templates use official SDKs (@modelcontextprotocol/sdk and fastmcp) and promote secure tool design through tight schema validation and descriptive metadata.
  • [SAFE]: The provided test utility (scripts/test-server.sh) is a benign shell script that utilizes the official MCP inspector to validate server responses locally.
  • [SAFE]: Remote deployment instructions for Cloudflare Workers use official templates and verified tooling from a trusted organization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:48 AM
Security Audit — agent-trust-hub — build-mcp-server