security MCP Server
Claude Code skill for comprehensive security auditing of GitHub repositories — specialized for AI agents, Skills, and MCPs
Discovered via github-topic:mcp and last synced 3mo ago.
Install instructions not detected yet
Check the source repository for the latest setup steps.
Chamador é o próprio usuário local — sem ganho
Authentication logic that can be bypassed
Categoria
HTML generated from external data without escaping
MCP tool descriptions designed to mislead the LLM
Category
Real API keys, tokens, passwords in tracked files
Undocumented HTTP calls carrying user data to external hosts
Installer scripts interpolating untrusted API data into inline code
Disabled signature verification, weak secrets, missing claim validation
Skill requests far more access than its task requires
Code downloads without integrity verification
MD5/SHA1 for passwords, deprecated algorithms, weak randomness
Skill instructs LLM to print full API responses containing PII
Unsanitized variables in subprocess/shell with untrusted input
`verify=False`, `rejectUnauthorized: false`, `InsecureSkipVerify`
Sub-skill invocations passing unsanitized user input downstream
User input in Jinja2/Handlebars/Go templates without escaping
XML parsers without external entity protection
User input directly concatenated into agent instructions
String concatenation in SQL queries
Tokens, passwords, CPF numbers logged in plaintext
`pickle.load`, `yaml.load` without `SafeLoader`, `marshal.loads`
Real secrets embedded in SKILL.md or LLM system prompts
Argumento CLI = valor confiável, sem vetor externo
MCP tool schemas accepting unnecessarily broad or dangerous parameters
真实性验证技能。分析用户提供的信息、消息、图片或内容,判断其真实性和可信度,识别虚假信息、AI生成内容或伪造内容。
Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators
Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS
Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. Covers TracingPolicy CRD authoring with kprobe/tracepoint hooks, in-kernel filtering via matchArgs/matchBinaries selectors, JSON event export, and integration with SIEM pipelines. Use when building kernel-level runtime security observability for Linux hosts or Kubernetes clusters.
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Open-source sandboxed agent harness for teams. Giving every employee a secured personal agent.
AI agent security scanner. Detect vulnerabilities in agent configurations, MCP servers, and tool permissions. Available as CLI, GitHub Action, ECC plugin, and GitHub App integration. 🛡️
A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)
Learn how to use the absolute-audit Claude skill. Complete guide with installation instructions and examples.
Learn how to use the token-scam-analysis Claude skill. Complete guide with installation instructions and examples.
Learn how to use the absolute-upgrade Claude skill. Complete guide with installation instructions and examples.