mcp-builder
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION] (SAFE): The
MCPConnectionStdioclass inscripts/connections.pyutilizesstdio_clientto execute commands. This is the standard mechanism for interacting with local MCP servers and is consistent with the skill's intended purpose of providing MCP connectivity. No evidence of shell injection or untrusted input passing to these commands was found in the static analysis. - [EXTERNAL_DOWNLOADS] (SAFE): The
scripts/requirements.txtfile specifiesanthropicandmcp. These are reputable libraries for AI tool integration. Per the trusted source policy, dependencies from the Anthropic organization are considered low risk for installation.
Audit Metadata