Server data from the Official MCP Registry
Scan AI agent skills and configs for hidden Unicode, prompt injection and exfiltration.
About
Scan AI agent skills and configs for hidden Unicode, prompt injection and exfiltration.
Remote endpoints: streamable-http: https://agent-skill-audit-mcp.mcpize.run/mcp
Security Report
Valid MCP server (2 strong, 3 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry. Trust signals: trusted author (4/4 approved).
Endpoint verified · Requires authentication · 1 issue found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Found in Source Code
Found by scanning the linked source code. This listing connects to a hosted endpoint, so none of this runs on your machine: it describes what the server software does where it is hosted.
How to Connect
Remote Plugin
No local installation needed. Your AI client connects to the remote endpoint directly.
Add this to your MCP configuration to connect:
{
"mcpServers": {
"io-github-tylerscomic-lab-agent-skill-audit-mcp": {
"url": "https://agent-skill-audit-mcp.mcpize.run/mcp"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
Agent Skill & Config Security Audit
Security scanner for AI agent skills and config files (SKILL.md, CLAUDE.md, AGENTS.md, .mcp.json, settings.json). Finds hidden Unicode instructions, prompt injection, exfiltration commands and over-broad permissions before you install a skill.
Scan a skill before you install it
Agent skills and instruction files are read straight into your agent's context, and some ship scripts it can run. Research on public skill registries has found prompt injection and credential-stealing payloads in a large share of them. Installing a third-party skill is closer to adding a dependency than opening a document, and nothing scans them. This does.
What it catches
- Hidden Unicode instructions: invisible "tag" characters that render as blank but that models can read, plus zero-width and bidi control characters. The hidden message is decoded for you.
- Prompt injection: "ignore previous instructions", "do not tell the user", fake system messages, approval bypasses.
- Download-and-execute and obfuscation:
curl | bash, base64-decode-and-run, large encoded blobs. - Exfiltration shapes: network commands that reference env vars or credential files, request-catcher and tunnel hosts, sensitive paths like
~/.sshand.aws/credentials. - Over-broad permissions: unrestricted
Bashin allowed-tools,Bash(*)pre-approvals, bypassed permissions. - Risky agent configs: unpinned
@latestMCP servers, inline secrets, plaintext remote servers, hooks that make network calls, API base-URL overrides, auto-trusted project MCP servers.
Tools
audit_skill_file: scan SKILL.md, CLAUDE.md, AGENTS.md, .cursorrules or a bundled script.audit_agent_config: audit .mcp.json or .claude/settings.json.reveal_hidden_text: find and decode invisible characters in any text, and return a cleaned copy.
Static analysis only. Nothing in your input is executed or fetched. A clean result is not a guarantee, so read bundled scripts too.
Use it
Hosted on MCPize with a free tier (10 calls a day). Remote MCP endpoint (streamable HTTP, API key from MCPize):
https://agent-skill-audit-mcp.mcpize.run/mcp
Or run it yourself:
npm install
node server.js # listens on :8080, MCP at /mcp
MIT licensed.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Worldmonitor
Freeby Koala73 · Developer Tools
Live markets, conflicts, country risk, chokepoints, energy, and China decision signals. 86 tools.
Paperclip
Freeby Paperclipai · Developer Tools
Trending hip-hop artist momentum scores across four cultural dimensions.
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
