Audit Tool Surface — Security skill for Claude Code
List every active tool across all MCP servers and flag cross-MCP duplicates and semantic overlaps.
How to install Audit Tool Surface
Installs to ~/.claude/skills/megabytespace-claude-skills-audit-tool-surface/SKILL.md
mkdir -p ~/.claude/skills/megabytespace-claude-skills-audit-tool-surface && curl -fsSL https://raw.githubusercontent.com/megabytespace/claude-skills/HEAD/commands/audit-tool-surface.md -o ~/.claude/skills/megabytespace-claude-skills-audit-tool-surface/SKILL.md Restart Claude Code, or start a new session, for it to be picked up.
What Audit Tool Surface does
description: List every active tool across all MCP servers and flag cross-MCP duplicates and semantic overlaps argument-hint: [--fix]
Audit the active tool surface across every local MCP server. Exact duplicates (same tool name in 2+ servers) confuse Claude — it cannot choose which to call. Semantic overlaps (e.g. `stripe.createCustomer` +
Alternatives in Security
- Cve MCP Server — Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS sco 1.2k ★
- Imcodes — The IM for agents 960 ★
- Google MCP Security Servers — Security Operations and Threat Intelligence MCP servers 453 ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Cross-Pollinate Hex MCP Servers
Diff-driven audit: find real transferable changes across hex-line-mcp, hex-ssh-mcp, hex-graph-mcp. Each delta
Colors
Run a color-only design audit — contrast, near-duplicates, dark mode, semantic coverage. Scoped variant of /ui
Claude Setup Audit
A Claude Code plugin that audits your whole setup — settings, permissions, hooks, MCP servers, skills, CLAUDE.
Mcpick
Vendor-neutral MCP configuration manager — one CLI to add, toggle, and audit MCP servers and skills across eve
Audit MCP Fleet
Healthcheck + drift detect + rotation-reminder across all MCP servers in ~/.claude/mcp-registry.json
Attack Surface
External attack-surface / recon audit of domains YOU OWN (your sites + subdomains, client sites under contract
Related Agents
Vault Librarian
Run vault maintenance: detect orphan notes, find broken wikilinks, validate frontmatter completeness, flag sta
Retool Endpoint Audit
Checks a migration slice against the main app's API surface — whether a local implementation duplicates an exi
Sqli Hunter
Active SQL injection hunter for an ingested program. Consumes webvuln-surface injection points + auth-context,