mcp-builder

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The toolkit includes scripts in the 'scripts/' directory designed to execute local shell commands to launch MCP servers during testing. This is standard functionality for MCP development and is restricted to the user's local environment.\n- [EXTERNAL_DOWNLOADS]: The documentation references official protocol specifications and SDK files from authoritative sources, including the modelcontextprotocol.io website and the official Model Context Protocol GitHub organization.\n- [REMOTE_CODE_EXECUTION]: The evaluation harness facilitates the execution of server code (e.g., Python or Node.js) in a subprocess to test its integration with an AI agent. This is a core feature of the provided developer tools.\n- [PROMPT_INJECTION]: The evaluation harness processes tool results from external MCP servers, which represents an indirect prompt injection surface. The harness mitigates this by instructing the agent to use structured XML tags (e.g., , , ) to separate external data from its own reasoning and final answers.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 04:14 AM