Toolward — Security skill for Claude Code
Security auditor for AI agent extensions — MCP servers, skills, plugins, connectors.
How to install Toolward
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open CatCatUncle/toolward and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Toolward does
Security auditor for AI agent extensions — MCP servers, skills, plugins, connectors. Finds prompt injection, tool poisoning, rug pulls, leaked keys and permission bypass. Static analysis only: never runs, installs or phones home for what it audits.
Alternatives in Security
- Token Scan — Meme coin and token security scan — checks for rug pull vectors (hidden mint, honeypot, fee manipulation, LP l 3.8k ★
- Memory Self Review — Mine recent agent history (claude-mem + usage stats) for recurring failures and repeated patterns, audit MEMOR 297 ★
- Claude Leaked Files — Mirrored snapshot of Claude Code's source (exposed 2026-03-31) preserved for educational purposes, defensive s 256 ★
README
Toolward
Your agent will run whatever you connect to it. Toolward reads it first.
A security auditor for the MCP servers, skills, plugins and connectors your agent loads.
Static analysis only — it never runs, installs or phones home for anything it audits.
面向 Agent 扩展的安全审查工具 · 中文文档
⚡ Quick start · Supported hosts · 37 rules · Threat model · CI · Limits · Licence
Related Skills
Claudit Sec
Security audit tool for Claude Desktop and Claude Code on macOS — single-command visibility into MCP servers,
Agent Security Super Skill
Comprehensive AI agent security skill — prompt injection defense, skill validation, memory poisoning preventio
Aiclean
Audit and clean up a Claude Code setup against Anthropic's current prompt-engineering guidance. Finds stale sc
Code Audit
Adversarial code review tree. Wraps /cc-tree:tree with the code-audit preset preselected — finds security / pe
Audit Live
Audit a deployed contract on a live chain. Pulls verified source from the block explorer, optionally forks the
Harden IDE Extensions
Audit IDE extensions and secure developer tool configs
Related Agents
Artifact Security Reviewer
Review a small shipped artifact for security: tool poisoning and instruction injection via descriptions, front
LLM Sec Review
LLM/agent security review specialist — prompt injection, the Agents Rule of Two, tool-call authorization, mode
Secret Purist
The paranoid sentinel of credential security. Use this agent to scan codebases and git history for leaked secr