skillaudit

security MCP Server

🛡️ Security scanner for AI agent skills — detect credential stealers, exfiltration, and malicious patterns before install

VerifiedInstall Ready
securitysecurity
2 views4 stars0 forksv1.1.0MIT

Why This Matters

Discovered via smithery and last synced 2mo ago.

VerifiedInstall Ready
Source
smithery
Stars
4
Last synced
2mo ago
Install
Instructions detected

Install

1. Install the package

npx skillaudit

2. Add to claude_desktop_config.json

{
  "mcpServers": {
    "skillaudit": {
      "command": "npx",
      "args": [
        "skillaudit"
      ]
    }
  }
}

Config file location: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) / %APPDATA%\Claude\claude_desktop_config.json (Windows)

11
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (11)

PERSISTENCE

Cron injection, systemd, LaunchAgents, pm2, nohup

MCP_SCHEMA_POISON

Hidden instructions in MCP tool descriptions/schemas

TIME_BOMB

Date-triggered activation, delayed execution

Category

Rules

SUPPLY_CHAIN

Remote code loading, curl\

Level

Score

Endpoint

Description

CRYPTO_THEFT

Wallet files, seed phrases, MetaMask vaults

CONTAINER_ESCAPE

Docker socket, nsenter, /proc traversal, LD_PRELOAD

0

No issues found

ENV_RECON

os.hostname, whoami, network interfaces, environment dump