agent-skill-audit-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@agent-skill-audit-mcpscan this SKILL.md for hidden instructions and injection"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Agent Skill & Config Security Audit
Security scanner for AI agent skills and config files (SKILL.md, CLAUDE.md, AGENTS.md, .mcp.json, settings.json). Finds hidden Unicode instructions, prompt injection, exfiltration commands and over-broad permissions before you install a skill.
Scan a skill before you install it
Agent skills and instruction files are read straight into your agent's context, and some ship scripts it can run. Research on public skill registries has found prompt injection and credential-stealing payloads in a large share of them. Installing a third-party skill is closer to adding a dependency than opening a document, and nothing scans them. This does.
Related MCP server: SkillsSafe
What it catches
Hidden Unicode instructions: invisible "tag" characters that render as blank but that models can read, plus zero-width and bidi control characters. The hidden message is decoded for you.
Prompt injection: "ignore previous instructions", "do not tell the user", fake system messages, approval bypasses.
Download-and-execute and obfuscation:
curl | bash, base64-decode-and-run, large encoded blobs.Exfiltration shapes: network commands that reference env vars or credential files, request-catcher and tunnel hosts, sensitive paths like
~/.sshand.aws/credentials.Over-broad permissions: unrestricted
Bashin allowed-tools,Bash(*)pre-approvals, bypassed permissions.Risky agent configs: unpinned
@latestMCP servers, inline secrets, plaintext remote servers, hooks that make network calls, API base-URL overrides, auto-trusted project MCP servers.
Tools
audit_skill_file: scan SKILL.md, CLAUDE.md, AGENTS.md, .cursorrules or a bundled script.audit_agent_config: audit .mcp.json or .claude/settings.json.reveal_hidden_text: find and decode invisible characters in any text, and return a cleaned copy.
Static analysis only. Nothing in your input is executed or fetched. A clean result is not a guarantee, so read bundled scripts too.
Use it
Hosted on MCPize with a free tier (10 calls a day). Remote MCP endpoint (streamable HTTP, API key from MCPize):
https://agent-skill-audit-mcp.mcpize.run/mcpOr run it yourself:
npm install
node server.js # listens on :8080, MCP at /mcpMIT licensed.
This server cannot be deployed
Maintenance
Related MCP Connectors
Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10.
Scan any public URL for hidden instructions aimed at AI agents (prompt injection). Free, no auth.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
The WAF for agents. Pattern-based + heuristic firewall scans prompts, RAG documents, tool argume...
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceStatic security scanner for AI agent skill packages that detects malicious SKILL.md files and bundled scripts before they run.15-
- AlicenseNot gradedqualityDmaintenanceSecurity scanner for AI agent skills, providing tools to scan skill files for threats such as credential theft and prompt injection.MIT
- AlicenseBqualityCmaintenanceProvides local, dependency-free security scanning tools for LLM configurations, prompts, RAG sources, and more, enabling AI coding agents to detect prompt injections and other vulnerabilities without external network access.8MIT
- AlicenseNot gradedqualityBmaintenanceAudits AI agent skills for safety using static, semantic, adversarial, and supply-chain analysis, providing scores and risk flags. Can be run via CLI, CI, or as an MCP tool from Claude Code, Cursor, and Codex.27 PyPI2Apache 2.0