Skip to main content
Glama

skillssafe-mcp

npm version MCP Registry License: MIT

MCP server for SkillsSafe — the security layer for AI agents.

Scan SKILL.md files, MCP configs, and system prompts for:

  • 🔐 Credential theft & data exfiltration

  • 💉 Prompt injection attacks

  • 👻 Zero-width character attacks

  • 🦠 ClawHavoc malware indicators

  • 🐚 Shell injection & reverse shells

  • 🔍 Scope creep & memory poisoning

Free. No API key. No signup.

Quick Start

Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "skillssafe": {
      "command": "npx",
      "args": ["-y", "skillssafe-mcp"]
    }
  }
}

Cursor

Add to .cursor/mcp.json:

{
  "mcpServers": {
    "skillssafe": {
      "command": "npx",
      "args": ["-y", "skillssafe-mcp"]
    }
  }
}

Direct SSE (Remote)

For clients that support SSE transport:

https://mcp.skillssafe.com/sse

Related MCP server: SkillsGuard

Tools

scan_skill

Scan an AI agent skill file for security threats before installation.

Parameters:
  url      - URL of skill to scan (GitHub raw URL, ClawHub URL, etc.)
  content  - Raw text content of skill to scan (alternative to url)
  lang     - Response language: "en" | "zh" | "ja" (default: "en")

Returns:
  decision    - INSTALL / REVIEW / BLOCK
  risk_score  - 0–100
  threats     - List of detected threats with severity
  scan_id     - ID for retrieving full report

get_report

Retrieve a previously generated scan report.

Parameters:
  scan_id  - Scan ID returned by scan_skill

Registry

🛡️ Security Audit

This project is indexed by SkillsSafe.

You can audit this MCP server before installing it:

openclaw mcp add skillssafe https://mcp.skillssafe.com/sse

Check out the community discussion on Cursor Forum.

License

MIT © SkillsSafe

A
license - permissive license
-
quality - not tested
D
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • F
    license
    -
    quality
    B
    maintenance
    Static security scanner for AI agent skill packages that detects malicious SKILL.md files and bundled scripts before they run.
    Last updated
    14
  • A
    license
    -
    quality
    C
    maintenance
    Provides a security scanner for AI agent skills and MCP servers, detecting threats like prompt injection, identity hijacking, and memory poisoning.
    Last updated
    22
    2
    MIT

View all related MCP servers

Related MCP Connectors

  • Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10.

  • Verify a skill, tool, or package for malicious behavior before your agent installs it. Hosted.

  • Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/GUCCI-atlasv/skillssafe-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server