Skip to main content
Ejecuta cualquier Skill en Manus
con un clic

detect-agent-credential-leak-mcp

Estrellas3
Forks0
Actualizado9 de julio de 2026 a las 16:16

Detect credential-looking material leaked in MCP tool-call responses. Consumes the native/canonical application-activity projection from ingest-mcp-proxy-ocsf, scans `tools/call` response bodies for high-confidence token patterns (AWS access keys, GitHub tokens, OpenAI keys, Slack tokens), and emits an OCSF Detection Finding (class 2004) without echoing the raw secret back out. Use when the user mentions MCP credential exposure, leaked tool results, agent secret leakage, or OWASP MCP credential exposure in tool responses. Do NOT use on `tools/list` metadata, non-MCP logs, or as a semantic prompt-injection classifier. This first slice is a deterministic regex detector on native MCP response bodies.

Instalación

Instalar con Codex o Claude Copia este prompt, pégalo en Codex, Claude u otro asistente, y deja que revise la página de la skill y la instale por ti.

Explorador de archivos
4 archivos
SKILL.md
readonly