Back to skill

Security audit

MCP Tool Maker

Security checks for vulnerabilities and agentic risk

Overview

This skill is an MCP code generator, but it can create unsafe wrappers that expose broad local code as tools and can be manipulated through generated Python source.

Install only for controlled local experiments. Review generated code before adding it to an MCP server, use only trusted source files with simple valid module names, avoid writing output over existing server files, and do not expose generated tools until each function has been explicitly approved.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
mcp_tool_maker.py:24
Finding

Generated Python Code Injection Through an Unsanitized Module Name

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
mcp_tool_maker.py:15
Finding

Unrestricted Exposure of Public and Nested Functions as MCP Tools

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Ae4

Medium
Category
analysis-evasion
Confidence
88% confidence
Finding

The skill contains extensive mojibake/mixed-script text, which obscures its real behavior and makes human review unreliable. Obfuscated or malformed text can hide risky instructions, capabilities, or trigger conditions, increasing the chance that unsafe functionality is approved or invoked without proper scrutiny.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill appears capable of generating code and writing output files, but it declares no explicit tool scope or permissions. In practice this can enable silent file modification or code generation side effects beyond what a reviewer or runtime policy expects, especially because the description explicitly mentions writing generated content into files and integrating into server code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad phrases like requests to generate tools or scan functions, which can overlap with ordinary user requests. This raises the risk of unintended activation, causing the skill to run code-generation or file-writing workflows when the user did not explicitly request this specific skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The secondary trigger section uses ambiguous keywords and loose activation language, including generic terms associated with help or the skill topic. In context, this broadens the skill's activation surface and can cause accidental routing to a skill that may generate or write files, compounding the risk created by undeclared write capability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring is entirely in Chinese and presents the skill's purpose and usage in a single language with no opt-in or alternative locale. Under the policy, a skill should not impose a language or locale unless it is explicitly optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

compile() call detected

Medium
Category
Dangerous Code Execution
Confidence
65% confidence
Finding

compile() creates code objects from strings. When combined with exec()/eval(), it enables obfuscated code execution.

Content

Scanner excerpt · mcp_tool_maker.py (reported line 12)May include surrounding context.

python
with open(filepath, encoding="utf-8") as f:
        source = f.read()
    
    tree = compile(source, filepath, 'exec', ast.PyCF_ONLY_AST)
    functions = []
    
    for node in ast.walk(tree):

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The generated code forcibly prepends a fixed local directory to sys.path, altering Python module resolution at runtime. This can cause imports to load unintended local modules, widen trust boundaries, and make the generated tool depend on a sensitive machine-specific path, increasing the risk of unsafe or surprising code execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill hard-codes a list of specific local project files and exposes their presence and sizes through the list command. For a generic MCP tool generator, this unnecessarily reveals local environment structure and encourages access to unrelated files, which can aid reconnaissance and accidental overreach.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.