MCP Security Checklist (SlowMist) — Security skill for Claude Code
Comprehensive checklist: input validation, rate limiting, RBAC, credential management, container hardening.
How to install MCP Security Checklist (SlowMist)
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open slowmist/MCP-Security-Checklist and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What MCP Security Checklist (SlowMist) does
[](https://twitter.com/slowmist_team)
Alternatives in Security
- Security Guardian — Comprehensive security analysis for RTK CLI tool, focusing on command injection, shell escaping, hook security 11.9k ★
- Skills Audit Report — Date: 2026-02-15 Auditor: Automated Skill Quality Audit Scope: Recently added skills in business-growth/, fina 5.3k ★
- Azure Key Vault .net — Cryptographic key management 1.8k ★
README
MCP Security Checklist: A Security Guide for the AI Tool Ecosystem
[](https://twitter.com/slowmist_team)
[English Version](./README.md), [中文版本](./README_CN.md)
Author Information
This security checklist was compiled and is maintained by [@SlowMist_Team](https://twitter.com/slowmist_team).
SlowMist, a global leader in blockchain ecosystem threat intelligence, aims to enhance security protection and safeguard user privacy during the integration of blockchain and AI ecosystems.
We sincerely thank [FENZ.AI](https://fenz.ai/) for their valuable contributions and support.
FENZ.AI redefines AI security with future-proof auditing. FENZ is the essential infrastructure for the AI era: "Superintelligence starts with super safety."
📚 Table of Contents
- Overview
- How to Use
- MCP Server (MCP Plugin) Security
- MCP Client/MCP HOST Security
- MCP Adaptation and Invocation Security on Different LLMs
- Multi-MCP Scenario Security
- Unique Security Points for Cryptocurrency-related MCPs
- MCP Security Self-Assessment Tools
- References
Overview
With the rapid development of large language models (LLMs), a variety of new AI tools have continued to emerge. Among them, tools based on the Model Context Protocol (MCP) standard have become a key bridge connecting LLMs with external tools and data sources. Since its release in late 2024, MCP has been widely adopted in mainstream AI applications such as Claude Desktop and Cursor. Various MCP Server marketplaces have also emerged, demonstrating strong ecosystem scalability.
...
Related Skills
ThinkWatch
Self-hosted AI API and MCP gateway for organizations: SSO and RBAC, per-user identity for MCP tool calls, PII
Arcjet Py
Runtime security for AI apps and agents: prompt injection detection, tool-call authorization, sensitive-data r
Auth Audit
Full auth & session audit: login flow, session/cookie security, JWT handling, middleware safety, privilege esc
Secure LLM Gateway
Security-focused gateway in front of an LLM API — auth, prompt-injection defense, output filtering, audit logg
Token Optimizer Skill
Token cost optimization skill for Claude Code — model routing (Opus/Sonnet/Haiku), extended thinking tuning, p
Docker Claude Code
new Run Claude Code in an isolated Docker container with multi-profile support, security hardening, best-pract
Related Agents
Network Security Engineer
Network Security Engineer (Tier 3): hardens the network perimeter and runtime — TLS 1.3/HSTS/ACME, nginx/Caddy
Production API Auditor
Audits API code for production readiness — error handling, input validation, authentication, rate limiting, st
Security Adversary
Red-team security reviewer for in-flight code diffs. Reads a git diff and produces a ranked critique focused o