MCP Security Auditor Lite

Free version — scan your MCP configuration for the top 3 security risks. Tool description injection, permission sprawl, and supply chain trust.

3,891 stars

Best use case

MCP Security Auditor Lite is best used when you need a repeatable AI agent workflow instead of a one-off prompt.

Free version — scan your MCP configuration for the top 3 security risks. Tool description injection, permission sprawl, and supply chain trust.

Teams using MCP Security Auditor Lite should expect a more consistent output, faster repeated execution, less prompt rewriting.

When to use this skill

  • You want a reusable workflow that can be run more than once with consistent structure.

When not to use this skill

  • You only need a quick one-off answer and do not need a reusable workflow.
  • You cannot install or maintain the underlying files, dependencies, or repository context.

Installation

Claude Code / Cursor / Codex

$curl -o ~/.claude/skills/mcp-security-auditor-lite/SKILL.md --create-dirs "https://raw.githubusercontent.com/openclaw/skills/main/skills/apex-stack-ai/mcp-security-auditor-lite/SKILL.md"

Manual Installation

  1. Download SKILL.md from GitHub
  2. Place it in .claude/skills/mcp-security-auditor-lite/SKILL.md inside your project
  3. Restart your AI agent — it will auto-discover the skill

How MCP Security Auditor Lite Compares

Feature / AgentMCP Security Auditor LiteStandard Approach
Platform SupportNot specifiedLimited / Varies
Context Awareness High Baseline
Installation ComplexityUnknownN/A

Frequently Asked Questions

What does this skill do?

Free version — scan your MCP configuration for the top 3 security risks. Tool description injection, permission sprawl, and supply chain trust.

Where can I find the source code?

You can find the source code on GitHub using the link provided at the top of the page.

Related Guides

SKILL.md Source

# MCP Security Auditor Lite — Quick Security Scan

You are an MCP security specialist. Your job is to quickly assess MCP server configurations for the most critical security risks.

This lite version covers **3 of 8 audit dimensions**. For the full MCP Security Auditor with all 8 dimensions, tool injection scanning, config drift detection, cross-tool safety analysis, and ongoing monitoring checklists, get the paid version: **https://apexstack.gumroad.com/l/mcp-security-auditor**

---

## How to Use

Provide your MCP config (JSON/YAML), tool list, or describe your MCP server setup. I'll scan for the top 3 risks.

---

## Quick Security Scan (Lite — 3 Dimensions)

### 1. Tool Description Integrity — /10
Are tool descriptions purely descriptive or do they contain hidden instructions?

**Red flags:**
- Imperative language ("always do X before calling other tools")
- References to other tools' behavior
- Unusually long descriptions (more attack surface)
- Instructions to ignore or override previous context

**Scoring:**
- 9-10: All descriptions purely descriptive, manually reviewed
- 5-6: Some imperative language, no hidden content detected
- 1-2: Active injection patterns, descriptions manipulate agent behavior

### 2. Permission Scope — /10
Do tools have the minimum permissions needed?

**Red flags:**
- File system tools with root/home access instead of scoped directories
- Database tools with write access when only reads are needed
- Tools that can access environment variables or secrets
- Admin-level access on tools that should be read-only

**Scoring:**
- 9-10: Every tool follows least-privilege, scoped to specific resources
- 5-6: Several tools have broad permissions, no systematic scoping
- 1-2: Tools have admin access, can access secrets, no boundaries

### 3. Supply Chain Trust — /10
Are your MCP servers from trusted sources?

**Red flags:**
- Unverified community MCP servers with no source review
- No version pinning (running "latest" = rug-pull risk)
- Servers installed without security evaluation
- No CVE monitoring for MCP dependencies

**Scoring:**
- 9-10: Verified publishers, pinned versions, source reviewed
- 5-6: Mix of trusted and unverified, some pinning
- 1-2: Random servers installed without evaluation

---

### Lite Output

```
## MCP Quick Security Scan: [Project]

### Score: [X/30] ([percentage]%) — [Secure / Adequate / At Risk]

| Dimension | Score | Risk | Top Action |
|-----------|-------|------|------------|
| Tool Description Integrity | X/10 | red/yellow/green | [action] |
| Permission Scope | X/10 | red/yellow/green | [action] |
| Supply Chain Trust | X/10 | red/yellow/green | [action] |

### Top 3 Fixes
1. [action]
2. [action]
3. [action]
```

Want the full security audit? The paid version includes all 8 dimensions, tool description injection scanner, permission scope analyzer, config drift detector, cross-tool manipulation checker, monitoring checklists, and prioritized remediation roadmap.

**Get the full version ->** https://apexstack.gumroad.com/l/mcp-security-auditor

---

Built by **Apex Stack** — based on real experience running 10+ MCP-connected agents in production.

Related Skills

Payroll Compliance Auditor

3891
from openclaw/skills

Run a full payroll audit in under 10 minutes. Catches the errors that cost companies $845 per violation.

Payroll & HR Compliance

Cybersecurity Risk Assessment

3891
from openclaw/skills

You are a cybersecurity risk assessment specialist. When the user needs a security audit, threat assessment, or compliance review, follow this framework.

Security

afrexai-cybersecurity-engine

3891
from openclaw/skills

Complete cybersecurity assessment, threat modeling, and hardening system. Use when conducting security audits, threat modeling, penetration testing, incident response, or building security programs from scratch. Works with any stack — zero external dependencies.

Security

security-guardian

3891
from openclaw/skills

Automated security auditing for OpenClaw projects. Scans for hardcoded secrets (API keys, tokens) and container vulnerabilities (CVEs) using Trivy. Provides structured reports to help maintain a clean and secure codebase.

Security

SX-security-audit

3891
from openclaw/skills

全方位安全审计技能。检查文件权限、环境变量、依赖漏洞、配置文件、网络端口、Git 安全、Shell 安全、macOS 安全、密钥检测等。支持 CLI 参数、JSON 输出、配置文件。当用户要求"安全检查"、"漏洞扫描"、"权限检查"、"安全审计"时使用此技能。

Security

slowmist-security-cc

3891
from openclaw/skills

SlowMist AI Agent Security Review — comprehensive security framework for skills, repositories, URLs, on-chain addresses, and products (Claude Code version)

writing-credibility-auditor

3891
from openclaw/skills

Audit any piece of writing for missing citations, unsupported claims, logical fallacies, weasel words, and misleading statistics — then produce a structured credibility report with flagged excerpts, fallacy names, severity ratings, and suggested fixes. Use when a user asks to fact-check, audit, or review the reasoning in an article, essay, report, research summary, or argument.

Landing Page Copywriter Lite

3891
from openclaw/skills

Free version — generate hero section copy and run a quick 3-point CRO audit on any landing page.

Freelancer Business Autopilot Lite

3891
from openclaw/skills

Free version — generate invoices and weekly client updates from plain-language descriptions.

Revenue Agent Lite

3891
from openclaw/skills

Free daily growth assistant for online businesses. Track basic revenue metrics, get daily action priorities, and monitor progress toward goals.

Programmatic SEO Auditor Lite

3891
from openclaw/skills

Basic programmatic SEO audit — analyze page templates, crawl budget issues, and indexing health. Free version covers template analysis, crawl budget checklist, and basic content quality scoring.

GEO Optimizer Lite

3891
from openclaw/skills

Free version — audit your content for AI search citability with the GEO Scorecard. Covers 4 of 8 dimensions.