Audit agent skills/prompts against 8 supply-chain attack patterns. Deterministic, no-LLM scanner.
MCPpedia last refreshed this data
io.github.sudo-ai-git/mcp-skill-sec is an MCP server that audit agent skills/prompts against 8 supply-chain attack patterns. Deterministic, no-LLM scanner. Its tool list has not been published yet over stdio, sse and http, requires no API key, and scores 54/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients - only the file and path differ.
{
"mcpServers": {
"skill-sec": {
"args": [],
"command": "mcp-skill-sec"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Audit agent skills/prompts against 8 supply-chain attack patterns. Deterministic, no-LLM scanner.
Run this in your terminal to verify the server starts. Then let us know if it worked - your result helps other developers.
uvx 'mcp-skill-sec' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories - click any category to see the underlying evidence.
No known CVEs.
Checked mcp-skill-sec against OSV.dev.
Be the first to review
Have you used this server?
Share your experience - it helps other developers decide.
Sign in to write a review.
Others in ai-ml
The official MCP server implementation for the Perplexity API Platform
Full Agent Swarm API and MCP server with local SQLite storage for multi-agent orchestration.
Read-only access to 71 Suede skills: discovery, install options, SEO audits, A-F grading.
An open-source AI agent that brings the power of Gemini directly into your terminal.
MCP Security Weekly
Get CVE alerts and security updates for io.github.sudo-ai-git/mcp-skill-sec and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.