MCP Security Checklist (SlowMist)
Description
[](https://twitter.com/slowmist_team)
Installation
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open the source below and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
README
MCP Security Checklist: A Security Guide for the AI Tool Ecosystem
[](https://twitter.com/slowmist_team)
[English Version](./README.md), [中文版本](./README_CN.md)
Author Information
This security checklist was compiled and is maintained by [@SlowMist_Team](https://twitter.com/slowmist_team).
SlowMist, a global leader in blockchain ecosystem threat intelligence, aims to enhance security protection and safeguard user privacy during the integration of blockchain and AI ecosystems.
We sincerely thank [FENZ.AI](https://fenz.ai/) for their valuable contributions and support.
FENZ.AI redefines AI security with future-proof auditing. FENZ is the essential infrastructure for the AI era: "Superintelligence starts with super safety."
📚 Table of Contents
- Overview
- How to Use
- MCP Server (MCP Plugin) Security
- MCP Client/MCP HOST Security
- MCP Adaptation and Invocation Security on Different LLMs
- Multi-MCP Scenario Security
- Unique Security Points for Cryptocurrency-related MCPs
- MCP Security Self-Assessment Tools
- References
Overview
With the rapid development of large language models (LLMs), a variety of new AI tools have continued to emerge. Among them, tools based on the Model Context Protocol (MCP) standard have become a key bridge connecting LLMs with external tools and data sources. Since its release in late 2024, MCP has been widely adopted in mainstream AI applications such as Claude Desktop and Cursor. Various MCP Server marketplaces have also emerged, demonstrating strong ecosystem scalability.
...
Related Skills
Fastapi Review
Review a FastAPI application for architecture, async correctness, dependency injection, Pydantic schemas, secu
Security Defense in Depth
Implement multi-layered testing and security best practices.
Security SecLists Official Repository
[OWASP Testing Guide](https://owasp.org/www-project-web-security-testing-guide/)
Security Threat Hunting with Sigma Rules
Use Sigma detection rules to hunt for threats and analyze security events
Security Maintenance Walkthrough - 2026-03-29
- Re-triaged the full 2026-03-15 security finding set against current `main` and wrote a fresh current-head re
Security Google Workspace Model Armor
Filter user-generated content for safety
Security Related Agents
Django Reviewer
Expert Django code reviewer specializing in ORM correctness, DRF patterns, migration safety, security misconfi
Token Auditor
Scans ui/src/ for hardcoded visual values, duplicate components, and shadcn replacement candidates; produces d
Gitnexus Security Boundary Reviewer
GitNexus security and trust-boundary reviewer. Use for auth, permissions, secrets, injection, unsafe parsing,