Security Pass

Review an MCP server for common security gaps: LLM-facing surfaces as injection vector (tools, resources, prompts, descriptions), scope blast radius, destructive ops without consent, upstream auth shape, input sinks (URL / path / roots / shell / schema strictness / ReDoS), tenant isolation, leakage through errors and telemetry, unbounded resources, and HTTP-mode deployment surface. Use before a release, after a batch of handler changes, or when the user asks for a security review, audit, or hardening pass. Produces grouped findings and a numbered options list.

cyanheads 2cda708 20.4 KB Updated

File contents

cyanheads/obsidian-mcp-server commit 2cda708398

Frequently asked questions

npx skillmds@latest add cyanheads/security-pass