Skip to main content
ClaudeWave
tylerscomic-lab avatar
tylerscomic-lab

agent-skill-audit-mcp

Ver en GitHub

Scan AI agent skills and configs for hidden Unicode, prompt injection and exfiltration.

MCP ServersRegistry oficial0 estrellas0 forks● JavaScriptMITActualizado today
ClaudeWave Trust Score
79/100
✓ Trusted
Passed
  • ✓Open-source license (MIT)
  • ✓Actively maintained (<30d)
  • ✓Clear description
  • ✓Documented (README)
Flags
  • !Install pipes a remote script into a shell (curl | sh)
Last scanned: 10/2/2026
Install in Claude Code / Claude Desktop
Method: Manual
Claude Code CLI
git clone https://github.com/tylerscomic-lab/agent-skill-audit-mcp
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "agent-skill-audit-mcp": {
      "command": "node",
      "args": ["/path/to/agent-skill-audit-mcp/dist/index.js"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
💡 Clone https://github.com/tylerscomic-lab/agent-skill-audit-mcp and follow its README for install instructions.
Casos de uso

Resumen de MCP Servers

# Agent Skill & Config Security Audit

Security scanner for AI agent skills and config files (SKILL.md, CLAUDE.md, AGENTS.md, .mcp.json, settings.json). Finds hidden Unicode instructions, prompt injection, exfiltration commands and over-broad permissions before you install a skill.

## Scan a skill before you install it
Agent skills and instruction files are read straight into your agent's context, and some ship scripts it can run. Research on public skill registries has found prompt injection and credential-stealing payloads in a large share of them. Installing a third-party skill is closer to adding a dependency than opening a document, and nothing scans them. This does.

## What it catches
- **Hidden Unicode instructions**: invisible "tag" characters that render as blank but that models can read, plus zero-width and bidi control characters. The hidden message is decoded for you.
- **Prompt injection**: "ignore previous instructions", "do not tell the user", fake system messages, approval bypasses.
- **Download-and-execute and obfuscation**: `curl | bash`, base64-decode-and-run, large encoded blobs.
- **Exfiltration shapes**: network commands that reference env vars or credential files, request-catcher and tunnel hosts, sensitive paths like `~/.ssh` and `.aws/credentials`.
- **Over-broad permissions**: unrestricted `Bash` in allowed-tools, `Bash(*)` pre-approvals, bypassed permissions.
- **Risky agent configs**: unpinned `@latest` MCP servers, inline secrets, plaintext remote servers, hooks that make network calls, API base-URL overrides, auto-trusted project MCP servers.

## Tools
- `audit_skill_file`: scan SKILL.md, CLAUDE.md, AGENTS.md, .cursorrules or a bundled script.
- `audit_agent_config`: audit .mcp.json or .claude/settings.json.
- `reveal_hidden_text`: find and decode invisible characters in any text, and return a cleaned copy.

Static analysis only. Nothing in your input is executed or fetched. A clean result is not a guarantee, so read bundled scripts too.

## Use it

Hosted on [MCPize](https://mcpize.com/mcp/agent-skill-audit-mcp) with a free tier (10 calls a day). Remote MCP endpoint (streamable HTTP, API key from MCPize):

```
https://agent-skill-audit-mcp.mcpize.run/mcp
```

Or run it yourself:

```bash
npm install
node server.js   # listens on :8080, MCP at /mcp
```

MIT licensed.

Lo que la gente pregunta sobre agent-skill-audit-mcp

¿Qué es tylerscomic-lab/agent-skill-audit-mcp?

+

tylerscomic-lab/agent-skill-audit-mcp es mcp servers para el ecosistema de Claude AI. Scan AI agent skills and configs for hidden Unicode, prompt injection and exfiltration. Tiene 0 estrellas en GitHub y su última actualización registrada es del 2026-10-01.

¿Cómo se instala agent-skill-audit-mcp?

+

Puedes instalar agent-skill-audit-mcp clonando el repositorio (https://github.com/tylerscomic-lab/agent-skill-audit-mcp) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.

¿Es seguro usar tylerscomic-lab/agent-skill-audit-mcp?

+

Nuestro agente de seguridad ha analizado tylerscomic-lab/agent-skill-audit-mcp y le ha asignado un Trust Score de 79/100 (tier: Trusted). Revisa el desglose completo de comprobaciones superadas y flags en esta página.

¿Quién mantiene tylerscomic-lab/agent-skill-audit-mcp?

+

tylerscomic-lab/agent-skill-audit-mcp es mantenido por tylerscomic-lab. La última actividad registrada en GitHub es del 2026-10-01, con 0 issues abiertos.

¿Hay alternativas a agent-skill-audit-mcp?

+

Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.

Despliega agent-skill-audit-mcp en tu cloud

Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.

¿Mantienes este repo? Añade un badge a tu README

Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.

Featured on ClaudeWave: tylerscomic-lab/agent-skill-audit-mcp
[![Featured on ClaudeWave](https://claudewave.com/api/badge/tylerscomic-lab-agent-skill-audit-mcp)](https://claudewave.com/repo/tylerscomic-lab-agent-skill-audit-mcp)
<a href="https://claudewave.com/repo/tylerscomic-lab-agent-skill-audit-mcp"><img src="https://claudewave.com/api/badge/tylerscomic-lab-agent-skill-audit-mcp" alt="Featured on ClaudeWave: tylerscomic-lab/agent-skill-audit-mcp" width="320" height="64" /></a>

Más MCP Servers

Alternativas a agent-skill-audit-mcp