Book a 30-minute demo →
Skill scan report

mcp-builder

View on GitHub
35 Medium This skill contains obfuscated or hidden content. Automated analysis flagged 1 additional risk pattern.

What this skill does

A framework for building MCP (Model-Client-Provider) servers, with support for authentication, widgets, and tooling. It is a development platform for building AI agent servers with UI and authenticati

github/mcp-use - Privilege Escalation - 10.5k stars

ThreatsPrivilege Escalation Obfuscation

Threat analysis

Privilege Escalation1 finding
Obfuscation1 finding

Skill info

Namemcp-use/mcp-builder
Registrygithub
Versionafcc55d
PURLpkg:github/mcp-use/mcp-use@afcc55d?skill=mcp-builder
Stars10.5k

Assessments (2)

Privilege Escalation1 finding HIGH
HIGH

Privilege Escalation via local-llm-review

references/authentication/better-auth.md

The `auth.ts` configuration file uses `process.env.BETTER_AUTH_SECRET!`  -  this is a potential risk if the secret is not properly managed or exposed in production. However, this is a standard practic
Obfuscation1 finding MEDIUM
MEDIUM

Obfuscation via local-llm-review

references/authentication/better-auth.md

The markdown file contains obfuscated or truncated URLs (e.g., `https://github.com/mcp-use/mcp-oauth-better-auth-template`). These are likely legitimate links and not obfuscation for malicious purpose

Badge

Add the Anomity scan badge for mcp-builder to your README.

Anomity Skill Check badge

Markdown
[![Anomity Skill Check](https://anomity.ai/skills/badge.svg)](https://anomity.ai/skills/github/mcp-use/mcp-builder/)
HTML
<a href="https://anomity.ai/skills/github/mcp-use/mcp-builder/"><img src="https://anomity.ai/skills/badge.svg" alt="Anomity Skill Check"></a>
Image URL
https://anomity.ai/skills/badge.svg

How Anomity governs this at runtime

Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.

Book a 30-minute demo to see your own skill inventory.

Methodology and disputes

Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of mcp-builder? Report an issue or request a rescan.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok