Skip to main content
Glama

mt_skill_audit

Audit AI agent skills by analyzing SKILL.md files for prompt injection, data exfiltration, and scope violations. Computes SHA-256 hashes and delivers scored security assessments to verify code integrity.

Instructions

Audit an AI agent skill (SKILL.md) for security risks.

Fetches the SKILL.md from a URL, computes its canonical SHA-256 hash, and runs an 8-point security audit checking for prompt injection, data exfiltration, tool scope violations, and metadata completeness. Score starts at 100 with deductions per finding. Passing score: >= 70.

Args: github_url: URL to the skill (GitHub repo or direct HTTPS link to SKILL.md)

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
github_urlYes

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Discloses the 8-point audit scope, SHA-256 hashing, and scoring mechanics (100 base, >=70 passing) despite no annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded one-line summary followed by technical details and isolated Args section; every sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Covers audit methodology and scoring adequately; presence of output schema excuses lack of return value documentation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Args section compensates for 0% schema description coverage by clarifying github_url accepts GitHub repos or direct HTTPS links to SKILL.md.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Specifically states it audits SKILL.md files for security risks via an 8-point check, clearly distinguishing from sibling credential/issue/verify tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Describes what it does but lacks explicit when-to-use guidance or differentiation from mt_skill_issue_vc/verify siblings.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/MoltyCel/mol-trust'

If you have feedback or need assistance with the MCP directory API, please join our Discord server