MCP Skills Vault — Security skill for Claude Code
Offline security check for MCP server configs (.mcp.json, VS Code, Cursor, Claude Code) — GitHub Action, pre-commit and CLI.
How to install MCP Skills Vault
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open froggychips/mcp-skills-vault and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What MCP Skills Vault does
Offline security check for MCP server configs (.mcp.json, VS Code, Cursor, Claude Code) — GitHub Action, pre-commit and CLI. Flags unpinned servers, plaintext secrets, typosquats, tool poisoning and toxic tool flows; pins and verifies known packages. Fails closed. Zero deps, no telemetry.
Alternatives in Security
- Om Vault Audit — Vault Audit 4.6k ★
- Claude Code Security Review — An AI-powered security review GitHub Action using Claude to analyze code changes for security vulnerabilities 3.9k ★
- Azure Key Vault .net — Cryptographic key management 1.8k ★
README
mcp-skills-vault
[](https://www.npmjs.com/package/@froggychips/mcp-vault) [](https://www.npmjs.com/package/@froggychips/mcp-vault) [](./LICENSE) [](./PHILOSOPHY.md) [](./tests)
**Homepage:** [mcp.froggychips.xyz](https://mcp.froggychips.xyz) · **npm:** [`@froggychips/mcp-vault`](https://www.npmjs.com/package/@froggychips/mcp-vault)
**Make MCP boring.** A deterministic registry + integrity scanner for [Model Context Protocol](https://modelcontextprotocol.io) servers, so installing one stops feeling like `curl | bash`.

$ npx -y @froggychips/mcp-vault scan
Stack: Langs: Node | DB: postgres | Infra: aws, teamcity, atlassian
Needs: database, infra, ci-cd, pm
── Recommended ──────────────────────────────────────────────
Core mcp-server-neon 10 tools score 105
Core mcp-server-aws 20 tools score 105
Core mcp-server-filesystem 10 tools score 105
Core mcp-server-memory 9 tools score 105
Recommended teamcity-mcp null tools score 65
── Heavy — scope before global install ──────────────────────
Experimental mcp-atlassian 72 tools ⚠ score 55
--toolsets jira,confluence
$ npx -y @froggychips/mcp-vault verify --offline
…
FAIL mcp-server-aws@1.0.27 (PyPI offline pin present for awslabs.core-mcp-server)
[FAIL] stored evidence: availability: yanked (observed 2026-09-17)
…
112 entries checked — 1 failure(s)
Without this vault vs. with it
| Without | With | |
|---|---|---|
| Discoverability | search GitHub, hope the README isn't lying | cura |
Related Skills
Review Code Security
Tiered application security audit (T1 pre-commit, T2 feature complete, T3 sprint end) covering OWASP, secrets,
Lintai
Offline-first, precision-first security linter for SKILLS, MCP, plugins, configs and other AI infrastructure.
Toolward
Security auditor for AI agent extensions — MCP servers, skills, plugins, connectors. Finds prompt injection, t
Diff Audit
PR / commit-scoped differential audit — audits only changed functions (plus 1-hop callers), flags removed secu
Agentseal
Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply cha
World Model MCP
world-model-mcp is a signed audit memory server for AI coding agents, delivered as an MCP tool. Every event Ed
Related Agents
PR Delivery Agent
Pre-PR secrets scanner, conventional-commit git stager, and GitHub PR publisher (or offline .patch generator w
Deployment Validator
Pre-deploy gate: env vars, secrets, flags, build, tests, rollback readiness. Use before deploying to staging o
Pre Commit Reviewer
Crosswalker pre-commit alignment auditor. Reviews staged changes against project conventions BEFORE commit — f