← all plugins

MCP Security Audit Pipeline

curated by SkillMD · plugin · 12 skills

Audit MCP servers for secrets exposure, shell injection, and supply chain risks.

Install the whole plugin (CLI)
npx skillmds add github/mcp-security-audit npx skillmds add github/agent-supply-chain npx skillmds add github/agent-owasp-compliance npx skillmds add affaan-m/security-scan npx skillmds add orchestra-research/prompt-guard npx skillmds add dontbesilent2025/dbs-skill-cleaner npx skillmds add zhaoxuya520/reverse-skill-router npx skillmds add zhaoxuya520/cloud-k8s npx skillmds add zhaoxuya520/pentest-tools npx skillmds add zhaoxuya520/js-reverse npx skillmds add zhaoxuya520/api-security npx skillmds add zhaoxuya520/browser-automation
⬇ Download

Skills in this plugin

  1. mcp-security-audit · github
    Audit MCP server configurations for security issues including secrets exposure, shell injection, unpinned dependencies, and unapproved servers.
    36.2k
    repo stars
  2. agent-supply-chain · github
    Verify supply chain integrity for AI agent plugins, tools, and dependencies by generating SHA-256 manifests, detecting tampered files, auditing dependency pinning, and enforcing promotion gates.
    36.2k
    repo stars
  3. agent-owasp-compliance · github
    Check any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks, scanning for controls and generating a compliance report.
    36.2k
    repo stars
  4. security-scan · affaan-m
    Audit Claude Code configuration files for security vulnerabilities, misconfigurations, and injection risks using AgentShield.
    226k
    repo stars
  5. prompt-guard · orchestra-research
    Detect prompt injections and jailbreak attempts in LLM applications using Meta's 86M parameter classifier. Filter user inputs, third-party data, and RAG documents with low latency and multilingual support.
    10.4k
    repo stars
  6. dbs-skill-cleaner · dontbesilent2025 bundle
    Scans installed or specified agent skills for advertising, covert commercial intent, task hijacking, suspicious external calls, and sensitive-data access. Reports findings first and quarantines only after explicit user confirmation.
    4
    installs
  7. reverse-skill-router · zhaoxuya520 bundle
    Routes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.
    12.8k
    repo stars
  8. cloud-k8s · zhaoxuya520 bundle
    Authorized security assessment for cloud, container, and Kubernetes environments covering metadata SSRF, IAM misconfigurations, container escape paths, and cluster RBAC review.
    12.8k
    repo stars
  9. pentest-tools · zhaoxuya520 bundle
    Provides a comprehensive penetration testing toolchain with 20+ security tools (Nmap, Nuclei, SQLMap, FFUF, Hashcat, etc.) exposed via MCP servers for authorized vulnerability scanning, exploitation, and reporting.
    12.8k
    repo stars
  10. js-reverse · zhaoxuya520 bundle
    Guides front-end JavaScript reverse engineering through a structured observe-capture-rebuild workflow using js-reverse MCP tools and optional jshookmcp for browser automation, CDP debugging, and runtime hooking.
    12.8k
    repo stars
  11. api-security · zhaoxuya520 bundle
    Authorized security assessment of REST, GraphQL, WebSocket, and SOAP APIs covering discovery, authentication, authorization, rate-limiting, and CI/CD integration.
    12.8k
    repo stars
  12. browser-automation · zhaoxuya520 bundle
    Unified automation entry point covering browser automation with Playwright and Windows desktop app automation with OpenReverse for GUI interaction, network capture, and reverse engineering workflows.
    12.8k
    repo stars