Audit History
building-mcp-servers - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 05:01 AM | 3 confirmed | 2 | No capability change |
| v8 | Jul 7, 2026, 08:36 PM | 7 confirmed | 2 | No capability change |
| v7 | Jul 5, 2026, 02:23 AM | 2 confirmed | 2 | Contains scripts |
| v6 | Jun 28, 2026, 10:48 AM | 2 confirmed | 1 | Contains scripts |
| v5 | Jan 16, 2026, 05:35 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 05:35 PM | No confirmed findings | 0 | Env variables Contains scripts |
| v3 | Jan 10, 2026, 10:35 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:35 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:35 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 05:01 AM
Most static alerts are false positives from Markdown, template strings, placeholders, or documented API examples. Two exposure patterns and three semantic design risks remain confirmed.
Confirmed security concerns (3)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (35)
🔑 Env variables (18)
⚙️ External commands (44)
Jul 7, 2026, 08:36 PM
Most static detections are false positives from Markdown examples, placeholder secrets, and TypeScript template literals. Confirmed risks are concentrated in the evaluation harness, which can launch user-supplied stdio commands and forward secrets, plus documentation that shows broad network exposure settings. No prompt-injection attempt was found in the reviewed files.
Confirmed security concerns (7)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (35)
🔑 Env variables (18)
⚙️ External commands (44)
Jul 5, 2026, 02:23 AM
Most static findings are false positives from Markdown examples, TypeScript template literals, placeholder URLs, and placeholder credential names. Confirmed issues are limited to security-relevant deployment guidance around broad HTTP exposure and the evaluation harness path that can launch user-specified commands. No evidence found of prompt injection text or malicious exfiltration intent.
Confirmed security concerns (2)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (35)
🔑 Env variables (18)
⚙️ External commands (44)
Jun 28, 2026, 10:48 AM
Static analysis produced many high and critical signals, but most are false positives from Markdown examples and headings. The confirmed risks are expected evaluator capabilities: launching a user-specified local MCP command, connecting to user-specified remote endpoints, and handling user-provided credentials. No evidence found of malicious intent, hidden exfiltration, real hardcoded secrets, weak cryptographic code, or prompt injection attempts.
Confirmed security concerns (2)
Needs review findings (1)
These findings came from uncertain legacy audit verdicts, so they require review but are not counted as confirmed security issues.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚡ Contains scripts (3)
⚙️ External commands (3)
🌐 Network access (3)
Detected Patterns
Jan 16, 2026, 05:35 PM
This is a documentation/guide skill containing markdown reference files and utility scripts for building MCP servers. All 575 static findings are FALSE POSITIVES - the analyzer misinterprets markdown code examples as executable security issues. The scripts (evaluation.py, connections.py) are legitimate MCP evaluation utilities using standard, documented patterns.
Risk Factors
⚙️ External commands (6)
🌐 Network access (3)
Jan 16, 2026, 05:35 PM
This is a documentation/guide skill containing markdown reference files and utility scripts for building MCP servers. All 575 static findings are FALSE POSITIVES - the analyzer misinterprets markdown code examples as executable security issues. The scripts (evaluation.py, connections.py) are legitimate MCP evaluation utilities using standard, documented patterns.
Risk Factors
⚙️ External commands (6)
🌐 Network access (3)
Jan 10, 2026, 10:35 AM
Documentation and guidance skill with Python evaluation scripts. Network calls are to Anthropic API and configurable MCP servers only. All code serves legitimate testing and documentation purposes with no data exfiltration or suspicious behavior patterns detected.
Risk Factors
⚡ Contains scripts (3)
🌐 Network access (3)
⚙️ External commands (1)
Jan 10, 2026, 10:35 AM
Documentation and guidance skill with Python evaluation scripts. Network calls are to Anthropic API and configurable MCP servers only. All code serves legitimate testing and documentation purposes with no data exfiltration or suspicious behavior patterns detected.
Risk Factors
⚡ Contains scripts (3)
🌐 Network access (3)
⚙️ External commands (1)
Jan 10, 2026, 10:35 AM
Documentation and guidance skill with Python evaluation scripts. Network calls are to Anthropic API and configurable MCP servers only. All code serves legitimate testing and documentation purposes with no data exfiltration or suspicious behavior patterns detected.