mcp-builder

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the retrieval of official MCP documentation and SDK information from the 'modelcontextprotocol.io' domain and official GitHub repositories. These sources are well-known and trusted within the developer community for this technology.
  • [COMMAND_EXECUTION]: The evaluation script ('scripts/evaluation.py') executes local MCP servers via the 'stdio' transport mechanism. This behavior is triggered by explicit user input and is the intended primary purpose of the evaluation harness.
  • [DATA_EXPOSURE]: The skill correctly instructs users to manage sensitive credentials, such as the 'ANTHROPIC_API_KEY', using environment variables rather than hardcoding them, which follows secure development practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 05:15 AM
Security Audit — agent-trust-hub — mcp-builder