mcp-builder
Pass
Audited by Gen Agent Trust Hub on Feb 19, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE] (SAFE): This skill consists exclusively of markdown instructions and does not package any scripts, configuration files, or executable binaries.
- [EXTERNAL_DOWNLOADS] (SAFE): The skill instructs the agent to fetch documentation from modelcontextprotocol.io and the official GitHub organization. These references are used for information gathering and context, not for automated script execution.
- [INDIRECT_PROMPT_INJECTION] (LOW): The skill creates an ingestion surface by reading external documentation. 1. Ingestion points: Documentation sites (modelcontextprotocol.io) and raw GitHub README files for SDKs. 2. Boundary markers: None. 3. Capability inventory: The skill suggests using npm and python tools for the user's project development. 4. Sanitization: None. This is a standard risk profile for documentation-centric skills.
Audit Metadata