mcp-builder
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the retrieval of official MCP documentation and SDK information from the 'modelcontextprotocol.io' domain and official GitHub repositories. These sources are well-known and trusted within the developer community for this technology.
- [COMMAND_EXECUTION]: The evaluation script ('scripts/evaluation.py') executes local MCP servers via the 'stdio' transport mechanism. This behavior is triggered by explicit user input and is the intended primary purpose of the evaluation harness.
- [DATA_EXPOSURE]: The skill correctly instructs users to manage sensitive credentials, such as the 'ANTHROPIC_API_KEY', using environment variables rather than hardcoding them, which follows secure development practices.
Audit Metadata