Auditing Skill And MCP Instructions

Lint the natural-language instruction text of an agent skill or MCP server, not its code: the skill body, the frontmatter description, tool descriptions, and parameter text a model reads and obeys. Covers instructions hidden in comments or markup, invisible and look-alike Unicode, override phrases that countermand earlier instructions, concealment directives that tell the agent to hide an action from the user, and instructions that steer the agent to read secrets and send them out. Use when reviewing a skill, an MCP server, or a marketplace entry before trusting it, or auditing what instruction text enters an agent's context. Every word the model reads is instruction surface; a planted instruction is the finding.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-skill-and-mcp-instructions commit 2562ec0760

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-skill-and-mcp-instructions