eval-mcp
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Downloads and executes the official @modelcontextprotocol/inspector tool from the NPM registry via npx. This tool is a well-known utility provided by the Model Context Protocol maintainers for server debugging.
- [COMMAND_EXECUTION]: Uses local bash scripts (fetch-tools.sh, analyze-schemas.sh, grade-selection.sh) to manage tool fetching, static schema analysis, and results grading.
- [COMMAND_EXECUTION]: Provides functionality to spawn local server processes (e.g., node server.js) when testing servers using the stdio transport, which is a core feature of the Model Context Protocol.
- [INDIRECT_PROMPT_INJECTION]: Ingests tool schemas from external MCP servers and user intents, which are luego interpolated into a subagent prompt for selection testing.
- Ingestion points: External tool schemas (tools.json) and user-provided test intents.
- Boundary markers: Employs JSON structure in subagent prompts to separate schema data from intent text, although it lacks explicit 'ignore instructions' directives for the ingested content.
- Capability inventory: Includes shell script execution and local process spawning.
- Sanitization: Does not perform explicit sanitization of tool descriptions or schemas before they are used in subagent prompts, though the results are only used for evaluation metrics.
Audit Metadata