skills/shipshitdev/skills/mcp-builder/Gen Agent Trust Hub

mcp-builder

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The evaluation script (scripts/evaluation.py) and connection handler (scripts/connections.py) facilitate the execution of local MCP servers as subprocesses. This behavior is user-controlled via command-line arguments (-c/--command and -a/--args) and is the intended mechanism for testing servers during development.
  • [EXTERNAL_DOWNLOADS]: The skill instructions (SKILL.md) direct the agent to fetch documentation and SDK information from official Model Context Protocol domains, including modelcontextprotocol.io, py.sdk.modelcontextprotocol.io, and ts.sdk.modelcontextprotocol.io. These are official service endpoints for the protocol being built.
  • [INDIRECT_PROMPT_INJECTION]: The evaluation harness (scripts/evaluation.py) processes user-provided XML files containing test questions. As these questions are interpolated into the system prompt for the evaluation sub-agent, there is a theoretical surface for indirect prompt injection if a malicious evaluation file is used.
  • Ingestion points: XML evaluation files are parsed in scripts/evaluation.py via parse_evaluation_file and the question text is passed to the agent loop.
  • Boundary markers: The EVALUATION_PROMPT uses XML-style tags (<summary>, <feedback>, <response>) to structure the agent's output, which provides structural boundaries for the task.
  • Capability inventory: The script possesses the ability to call the Anthropic Messages API and execute local commands or network requests via the connections.py module to interact with MCP servers.
  • Sanitization: The script relies on the structural prompting of the evaluation agent rather than explicit input sanitization of the question content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — mcp-builder