{"data":{"skill":{"slug":"mcp-use-mcp-builder","name":"mcp-builder","icon":"📦","repo":"https://github.com/mcp-use/mcp-use/tree/main/skills/mcp-builder/","status":"approved","author":"mcp-use","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"88a015cb-2f36-4459-8b48-1d767ce5eaae","skill_id":"fc219f52-e999-4a9b-b3f8-89d4d6ff3dee","version":2,"content_hash":"1a2a1ea56f8178f2a2f6af08ba084929","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis reported many high and critical patterns, but review found they are mostly Markdown code examples, method names, license text, and documentation snippets rather than executable skill behavior. No prompt injection attempt or confirmed malicious intent was found. The skill still carries medium risk because copied examples include environment secrets, network calls, and file reads that need access controls in generated MCP servers.","remediation":[],"risk_factor_evidence":[{"factor":"env_access","evidence":[{"file":"evals/implementation.json","line_end":16,"line_start":15},{"file":"references/tools-and-resources.md","line_end":283,"line_start":271},{"file":"references/widgets.md","line_end":359,"line_start":356}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":7,"line_start":4},{"file":"evals/README.md","line_end":23,"line_start":20}]},{"factor":"network","evidence":[{"file":"LICENSE.txt","line_end":3,"line_start":1},{"file":"references/tools-and-resources.md","line_end":283,"line_start":271},{"file":"references/widgets.md","line_end":205,"line_start":202}]},{"factor":"filesystem","evidence":[{"file":"references/resource-templates.md","line_end":58,"line_start":50},{"file":"references/response-helpers.md","line_end":128,"line_start":126},{"file":"references/response-helpers.md","line_end":142,"line_start":141}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Copyable API Key in URL Query Example","verdict":"TRUE_POSITIVE_DOCUMENTATION_RISK","locations":[{"file":"references/tools-and-resources.md","line_end":283,"line_start":271},{"file":"evals/implementation.json","line_end":16,"line_start":15}],"confidence":0.78,"description":"The documentation shows an API key read from an environment variable and placed into a URL query string. If copied into a real MCP server, the key could be exposed through logs, caches, browser history, or upstream analytics.","confidence_reasoning":"The exact example reads WEATHER_API_KEY and interpolates it into a fetch URL. It is documentation rather than active code, so the risk depends on a user copying the pattern."},{"title":"Unconstrained File Resource Template Example","verdict":"TRUE_POSITIVE_DOCUMENTATION_RISK","locations":[{"file":"references/resource-templates.md","line_end":58,"line_start":50}],"confidence":0.72,"description":"The resource template example maps a user-controlled path into a file read without showing allow-listing, path normalization, or workspace boundaries. If copied directly, a generated MCP server could expose unintended local files.","confidence_reasoning":"The example directly connects a URI path parameter to readFile(path). It is a sample snippet, but the missing boundary checks are a realistic implementation risk."}],"low_findings":[{"title":"Static Weak Cryptography Matches Are False Positives","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":7,"line_start":3},{"file":"references/design-and-architecture.md","line_end":10,"line_start":1},{"file":"LICENSE.txt","line_end":25,"line_start":25}],"confidence":0.91,"description":"The weak cryptography alerts align with Markdown headings, prose, method names, or license text. No evidence found of cryptographic APIs, hash functions, password handling, or encryption code in the reviewed skill files.","confidence_reasoning":"Manual review found documentation text and no executable cryptographic logic. The repeated alerts are consistent with token-level matches in Markdown and license prose."},{"title":"Static External Command Matches Are Mostly Markdown","verdict":"FALSE_POSITIVE_WITH_MINOR_USER_ACTION_RISK","locations":[{"file":"SKILL.md","line_end":7,"line_start":4},{"file":"evals/README.md","line_end":23,"line_start":20},{"file":"references/widgets.md","line_end":39,"line_start":37}],"confidence":0.88,"description":"Most command execution alerts come from code fences, inline method names, and eval instructions. The only direct shell command is a visible npx install command for the replacement skill, not hidden execution by this skill.","confidence_reasoning":"The referenced files are Markdown or JSON evaluation text. No script file, package hook, or automatic command execution path was found."},{"title":"Critical Combined Heuristic Not Confirmed","verdict":"FALSE_POSITIVE","locations":[{"file":"references/tools-and-resources.md","line_end":283,"line_start":271},{"file":"SKILL.md","line_end":7,"line_start":4},{"file":"references/widgets.md","line_end":205,"line_start":202}],"confidence":0.84,"description":"The scanner combined code examples for environment variables, network calls, and command-like text into a critical heuristic. Review found no data exfiltration flow, hidden network endpoint, or executable automation inside the skill itself.","confidence_reasoning":"The suspicious categories are present only as guidance for MCP apps. The skill content does not itself run code or transmit collected secrets."}],"dangerous_patterns":[{"title":"Secret in Query String Pattern","verdict":"DOCUMENTATION_PATTERN","locations":[{"file":"references/tools-and-resources.md","line_end":283,"line_start":275}],"confidence":0.8,"description":"The weather API example places an API key into a URL query parameter. Generated code should prefer provider-supported authorization headers or other non-URL secret transport.","confidence_reasoning":"The pattern is explicit in a code example and is security-sensitive when reused. It is not active code in this skill."},{"title":"User Path to File Read Pattern","verdict":"DOCUMENTATION_PATTERN","locations":[{"file":"references/resource-templates.md","line_end":58,"line_start":50}],"confidence":0.76,"description":"The resource template example reads a path derived from a URI parameter. Generated servers should constrain paths to an allow-listed base directory and reject traversal.","confidence_reasoning":"The path-to-readFile flow is visible in the example. It remains a documentation risk rather than a confirmed vulnerability in this skill package."}],"files_scanned":12,"total_lines":1666,"audit_model":"codex","audited_at":"2026-06-30T08:14:12.56+00:00","created_at":"2026-06-30T10:03:09.538019+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":2,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":3,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}