Auditing MCP Servers

Audit Model Context Protocol servers for injection surfaces, excessive tool scope, authorization gaps, resource over-exposure, and transport weaknesses across stdio, SSE, and Streamable HTTP deployments. Use when reviewing an MCP server implementation, assessing tool definitions for injection or description manipulation risk, auditing the trust boundary between an AI agent and MCP tools, or reviewing MCP server deployment for authentication and authorization controls.

trilwu 44c57e5 18.3 KB Updated

File contents

trilwu/secskills/tree/main/secskills-core/skills/auditing-mcp-servers commit 44c57e5df1

Frequently asked questions

npx skillmds add trilwu/auditing-mcp-servers