mcp-builder

Pass

Audited by Gen Agent Trust Hub on Mar 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The evaluation harness in scripts/evaluation.py and the connection logic in scripts/connections.py enable the execution of local MCP servers through the stdio transport, using user-supplied command-line arguments.\n- [EXTERNAL_DOWNLOADS]: The documentation directs developers to fetch official protocol specifications and SDK details from the modelcontextprotocol GitHub organization, which is a recognized and authoritative source.\n- [PROMPT_INJECTION]: The utility in scripts/evaluation.py processes question-and-answer pairs from an external XML file for AI testing purposes. This creates a surface for indirect prompt injection if malicious data is provided in the evaluation set, although this risk is localized to the testing process.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 5, 2026, 07:56 AM