skill-security-auditor
Scan Claude skills and MCP servers for suspicious security patterns.
Scan Claude skills and MCP servers for suspicious security patterns.
Skill Security Auditor checks skill files and MCP servers for dangerous commands, prompt injection, credential access, risky tool combinations, supply-chain issues, and MCP-specific flaws such as SSRF or path traversal. It produces a heuristic risk score and report, but its static analysis can miss sophisticated behavior and should be paired with expert inspection.
Resource types
Use cases
Platforms
Audit suspension risks in a Claude Code working environment.
Check whether a specific CVE actually applies to your environment.
Runtime
Capabilities
Public GitHub facts last synced Jul 10, 2026.
Store and inject development secrets through 1Password from Claude Code.
Audit a deployed public app for production gaps missed during coding.