auditing-mcp-servers-for-tool-poisoning

mukul975/auditing-mcp-servers-for-tool-poisoning · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Scan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.

SKILL.md

Files

This skill is a package of 5 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.2 KB
  • 📄standards.md 1.5 KB
  • 📁scripts
  • ⚙️agent.py 5.6 KB
  • 📄LICENSE 11.0 KB

Related

  1. mcp-security-audit · github
    Audit MCP server configurations for security issues including secrets exposure, shell injection, unpinned dependencies, and unapproved servers.
    36.2k
    repo stars
  2. snyk-agent-scan · agentskillexchange
    Scans AI agents, MCP servers, and skills for security vulnerabilities from the command line, detecting prompt injections, tool poisoning, toxic flows, malware payloads, and credential handling issues across 15+ risk categories.
    28
    repo stars
  3. xxe · shulkwisec
    Detect and exploit XML External Entity (XXE) injection vulnerabilities in XML parsers, including file disclosure, SSRF, and blind out-of-band exfiltration.
    21
    repo stars
  4. ai-security · alirezarezvani bundle
    Assess AI/ML systems for prompt injection, jailbreak vulnerabilities, model inversion risk, data poisoning exposure, and agent tool abuse, with MITRE ATLAS mapping and guardrail recommendations.
    20.4k
    repo stars
  5. mcp-builder · antigravity bundle
    Guides the creation of MCP servers that enable LLMs to interact with external services through well-designed tools.
    42.4k
    repo stars
  6. skill-scanner · getsentry bundle
    Scans agent skills for security issues including prompt injection, malicious scripts, excessive permissions, secret exposure, and supply chain risks.
    845
    repo stars

Frequently asked questions

How do I install the auditing-mcp-servers-for-tool-poisoning skill?

Run npx skillmds add mukul975/auditing-mcp-servers-for-tool-poisoning in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the auditing-mcp-servers-for-tool-poisoning skill do?

Scan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure. It is listed under Security, AI & ML, Agent Building, Penetration Testing, Vulnerability Scanning on SkillMD.

Is auditing-mcp-servers-for-tool-poisoning safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: CAUTION, Skill Scanner: WARNING. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with auditing-mcp-servers-for-tool-poisoning?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is auditing-mcp-servers-for-tool-poisoning free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published auditing-mcp-servers-for-tool-poisoning?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.