mcp-builder
What this skill does
A framework for building MCP (Model-Client-Provider) servers, with support for authentication, widgets, and tooling. It is a development platform for building AI agent servers with UI and authenticati
github/mcp-use - Privilege Escalation - 10.5k stars
Threat analysis
Skill info
pkg:github/mcp-use/mcp-use@afcc55d?skill=mcp-builderAssessments (2)
Privilege Escalation
Privilege Escalation via local-llm-review
references/authentication/better-auth.md
The `auth.ts` configuration file uses `process.env.BETTER_AUTH_SECRET!` - this is a potential risk if the secret is not properly managed or exposed in production. However, this is a standard practicObfuscation
Obfuscation via local-llm-review
references/authentication/better-auth.md
The markdown file contains obfuscated or truncated URLs (e.g., `https://github.com/mcp-use/mcp-oauth-better-auth-template`). These are likely legitimate links and not obfuscation for malicious purposeBadge
Add the Anomity scan badge for mcp-builder to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of mcp-builder? Report an issue or request a rescan.




