mcp-builder

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/evaluation.py

This module does not show explicit malicious payload behavior (no obfuscated code, no credential theft, no direct system command execution). However, it implements an agent-style capability pathway where untrusted model output directly drives arbitrary MCP tool calls (tool_name/tool_input are not validated/allowlisted in this module). Tool results and even tracebacks are fed back into the LLM context, increasing the chance of unintended actions or information leakage if MCP tools have sensitive capabilities. Risk level is therefore driven by tool/connection permissions and sandboxing outside this fragment.

Confidence: 62%Severity: 68%
Audit Metadata
Analyzed At
Sep 8, 2026, 06:57 AM
Package URL
pkg:socket/skills-sh/seaworld008%2Fcommonly-used-high-value-skills%2Fmcp-builder%2F@0381db3accb72d57fb5f305d5e52392675d688fc6c50396774fc0bf7be7c60b3
Security Audit — socket — mcp-builder