mcp-builder
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The evaluation script (
scripts/evaluation.py) and connection handler (scripts/connections.py) facilitate the execution of local MCP servers as subprocesses. This behavior is user-controlled via command-line arguments (-c/--commandand-a/--args) and is the intended mechanism for testing servers during development. - [EXTERNAL_DOWNLOADS]: The skill instructions (
SKILL.md) direct the agent to fetch documentation and SDK information from official Model Context Protocol domains, includingmodelcontextprotocol.io,py.sdk.modelcontextprotocol.io, andts.sdk.modelcontextprotocol.io. These are official service endpoints for the protocol being built. - [INDIRECT_PROMPT_INJECTION]: The evaluation harness (
scripts/evaluation.py) processes user-provided XML files containing test questions. As these questions are interpolated into the system prompt for the evaluation sub-agent, there is a theoretical surface for indirect prompt injection if a malicious evaluation file is used. - Ingestion points: XML evaluation files are parsed in
scripts/evaluation.pyviaparse_evaluation_fileand the question text is passed to the agent loop. - Boundary markers: The
EVALUATION_PROMPTuses XML-style tags (<summary>,<feedback>,<response>) to structure the agent's output, which provides structural boundaries for the task. - Capability inventory: The script possesses the ability to call the Anthropic Messages API and execute local commands or network requests via the
connections.pymodule to interact with MCP servers. - Sanitization: The script relies on the structural prompting of the evaluation agent rather than explicit input sanitization of the question content.
Audit Metadata