Skip to main content

security-audit

Security auditor for Claude skills, MCP servers, and pre-publish deployments. Use PROACTIVELY, not only when asked. Trigger whenever: a skill or MCP is about to run, is newly installed, or changed; the first time a skill/MCP is used this session; an MCP config, settings.json, or .mcp.json is edited; OR before pushing, publishing, deploying, or uploading anything to GitHub, npm, a website, or any production surface. It vets skills & MCPs for hidden-instruction, exfiltration, and supply-chain risk (including following external links and re-checking that a trusted redirect wasn't repointed to something hostile), and runs an exposure gate that blocks secrets, API keys, tokens, PII, and EXIF from being published. Also trigger when an npm supply-chain attack is disclosed or the user asks whether they are affected by one: the supply-chain mode sweeps every Node project on the machine (lockfile-resolved versions, node_modules, dropped IOC files) plus system persistence (crontab, launch items, global npm, shell rc) ag

Aller à l'installation

Informations de source

Dépôt
roeea2/security-audit-skill
Dernière activité de la source
17 août 2026 à 16:45
Langue détectée de SKILL.md
anglais
Étoiles
0
Forks
0

Options d'installation

Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.

Vérifiez les fichiers source

Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.