MCP Security Audit Pipeline
curated by SkillMD · plugin · 12 skills
Audit MCP servers for secrets exposure, shell injection, and supply chain risks.
Install the whole plugin (CLI)
npx skillmds add github/mcp-security-audit
npx skillmds add github/agent-supply-chain
npx skillmds add github/agent-owasp-compliance
npx skillmds add affaan-m/security-scan
npx skillmds add orchestra-research/prompt-guard
npx skillmds add dontbesilent2025/dbs-skill-cleaner
npx skillmds add zhaoxuya520/reverse-skill-router
npx skillmds add zhaoxuya520/cloud-k8s
npx skillmds add zhaoxuya520/pentest-tools
npx skillmds add zhaoxuya520/js-reverse
npx skillmds add zhaoxuya520/api-security
npx skillmds add zhaoxuya520/browser-automationSkills in this plugin
- ▌ mcp-security-audit · githubAudit MCP server configurations for security issues including secrets exposure, shell injection, unpinned dependencies, and unapproved servers.
- ▌ agent-supply-chain · githubVerify supply chain integrity for AI agent plugins, tools, and dependencies by generating SHA-256 manifests, detecting tampered files, auditing dependency pinning, and enforcing promotion gates.
- ▌ agent-owasp-compliance · githubCheck any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks, scanning for controls and generating a compliance report.
- ▌ security-scan · affaan-mAudit Claude Code configuration files for security vulnerabilities, misconfigurations, and injection risks using AgentShield.
- ▌ prompt-guard · orchestra-researchDetect prompt injections and jailbreak attempts in LLM applications using Meta's 86M parameter classifier. Filter user inputs, third-party data, and RAG documents with low latency and multilingual support.
- ▌ dbs-skill-cleaner · dontbesilent2025 bundleScans installed or specified agent skills for advertising, covert commercial intent, task hijacking, suspicious external calls, and sensitive-data access. Reports findings first and quarantines only after explicit user confirmation.
- ▌ reverse-skill-router · zhaoxuya520 bundleRoutes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.
- ▌ cloud-k8s · zhaoxuya520 bundleAuthorized security assessment for cloud, container, and Kubernetes environments covering metadata SSRF, IAM misconfigurations, container escape paths, and cluster RBAC review.
- ▌ pentest-tools · zhaoxuya520 bundleProvides a comprehensive penetration testing toolchain with 20+ security tools (Nmap, Nuclei, SQLMap, FFUF, Hashcat, etc.) exposed via MCP servers for authorized vulnerability scanning, exploitation, and reporting.
- ▌ js-reverse · zhaoxuya520 bundleGuides front-end JavaScript reverse engineering through a structured observe-capture-rebuild workflow using js-reverse MCP tools and optional jshookmcp for browser automation, CDP debugging, and runtime hooking.
- ▌ api-security · zhaoxuya520 bundleAuthorized security assessment of REST, GraphQL, WebSocket, and SOAP APIs covering discovery, authentication, authorization, rate-limiting, and CI/CD integration.
- ▌ browser-automation · zhaoxuya520 bundleUnified automation entry point covering browser automation with Playwright and Windows desktop app automation with OpenReverse for GUI interaction, network capture, and reverse engineering workflows.