mcp-builder

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION] (SAFE): The MCPConnectionStdio class in scripts/connections.py utilizes stdio_client to execute commands. This is the standard mechanism for interacting with local MCP servers and is consistent with the skill's intended purpose of providing MCP connectivity. No evidence of shell injection or untrusted input passing to these commands was found in the static analysis.
  • [EXTERNAL_DOWNLOADS] (SAFE): The scripts/requirements.txt file specifies anthropic and mcp. These are reputable libraries for AI tool integration. Per the trusted source policy, dependencies from the Anthropic organization are considered low risk for installation.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:03 PM