Project overview
Skill Security Auditor checks skill files and MCP servers for dangerous commands, prompt injection, credential access, risky tool combinations, supply-chain issues, and MCP-specific flaws such as SSRF or path traversal. It produces a heuristic risk score and report, but its static analysis can miss sophisticated behavior and should be paired with expert inspection.
Repository facts
- Primary language
- Shell
- License
- MIT
- Repository updated
- Apr 17, 2026
- Default branch
- main
Resource types
General skill
Use cases
Security and privacyCode review and quality
Platforms
Claude Code, Codex, and more
Runtime
Command lineSandboxed
Capabilities
Security guardrailTool useVerification and evals