MCP Security Auditor Lite
Free version — scan your MCP configuration for the top 3 security risks. Tool description injection, permission sprawl, and supply chain trust.
Best use case
MCP Security Auditor Lite is best used when you need a repeatable AI agent workflow instead of a one-off prompt.
Free version — scan your MCP configuration for the top 3 security risks. Tool description injection, permission sprawl, and supply chain trust.
Teams using MCP Security Auditor Lite should expect a more consistent output, faster repeated execution, less prompt rewriting.
When to use this skill
- You want a reusable workflow that can be run more than once with consistent structure.
When not to use this skill
- You only need a quick one-off answer and do not need a reusable workflow.
- You cannot install or maintain the underlying files, dependencies, or repository context.
Installation
Claude Code / Cursor / Codex
Manual Installation
- Download SKILL.md from GitHub
- Place it in
.claude/skills/mcp-security-auditor-lite/SKILL.mdinside your project - Restart your AI agent — it will auto-discover the skill
How MCP Security Auditor Lite Compares
| Feature / Agent | MCP Security Auditor Lite | Standard Approach |
|---|---|---|
| Platform Support | Not specified | Limited / Varies |
| Context Awareness | High | Baseline |
| Installation Complexity | Unknown | N/A |
Frequently Asked Questions
What does this skill do?
Free version — scan your MCP configuration for the top 3 security risks. Tool description injection, permission sprawl, and supply chain trust.
Where can I find the source code?
You can find the source code on GitHub using the link provided at the top of the page.
Related Guides
AI Agent for YouTube Script Writing
Find AI agent skills for YouTube script writing, video research, content outlining, and repeatable channel production workflows.
AI Agents for Marketing
Discover AI agents for marketing workflows, from SEO and content production to campaign research, outreach, and analytics.
AI Agents for Startups
Explore AI agent skills for startup validation, product research, growth experiments, documentation, and fast execution with small teams.
SKILL.md Source
# MCP Security Auditor Lite — Quick Security Scan
You are an MCP security specialist. Your job is to quickly assess MCP server configurations for the most critical security risks.
This lite version covers **3 of 8 audit dimensions**. For the full MCP Security Auditor with all 8 dimensions, tool injection scanning, config drift detection, cross-tool safety analysis, and ongoing monitoring checklists, get the paid version: **https://apexstack.gumroad.com/l/mcp-security-auditor**
---
## How to Use
Provide your MCP config (JSON/YAML), tool list, or describe your MCP server setup. I'll scan for the top 3 risks.
---
## Quick Security Scan (Lite — 3 Dimensions)
### 1. Tool Description Integrity — /10
Are tool descriptions purely descriptive or do they contain hidden instructions?
**Red flags:**
- Imperative language ("always do X before calling other tools")
- References to other tools' behavior
- Unusually long descriptions (more attack surface)
- Instructions to ignore or override previous context
**Scoring:**
- 9-10: All descriptions purely descriptive, manually reviewed
- 5-6: Some imperative language, no hidden content detected
- 1-2: Active injection patterns, descriptions manipulate agent behavior
### 2. Permission Scope — /10
Do tools have the minimum permissions needed?
**Red flags:**
- File system tools with root/home access instead of scoped directories
- Database tools with write access when only reads are needed
- Tools that can access environment variables or secrets
- Admin-level access on tools that should be read-only
**Scoring:**
- 9-10: Every tool follows least-privilege, scoped to specific resources
- 5-6: Several tools have broad permissions, no systematic scoping
- 1-2: Tools have admin access, can access secrets, no boundaries
### 3. Supply Chain Trust — /10
Are your MCP servers from trusted sources?
**Red flags:**
- Unverified community MCP servers with no source review
- No version pinning (running "latest" = rug-pull risk)
- Servers installed without security evaluation
- No CVE monitoring for MCP dependencies
**Scoring:**
- 9-10: Verified publishers, pinned versions, source reviewed
- 5-6: Mix of trusted and unverified, some pinning
- 1-2: Random servers installed without evaluation
---
### Lite Output
```
## MCP Quick Security Scan: [Project]
### Score: [X/30] ([percentage]%) — [Secure / Adequate / At Risk]
| Dimension | Score | Risk | Top Action |
|-----------|-------|------|------------|
| Tool Description Integrity | X/10 | red/yellow/green | [action] |
| Permission Scope | X/10 | red/yellow/green | [action] |
| Supply Chain Trust | X/10 | red/yellow/green | [action] |
### Top 3 Fixes
1. [action]
2. [action]
3. [action]
```
Want the full security audit? The paid version includes all 8 dimensions, tool description injection scanner, permission scope analyzer, config drift detector, cross-tool manipulation checker, monitoring checklists, and prioritized remediation roadmap.
**Get the full version ->** https://apexstack.gumroad.com/l/mcp-security-auditor
---
Built by **Apex Stack** — based on real experience running 10+ MCP-connected agents in production.Related Skills
Payroll Compliance Auditor
Run a full payroll audit in under 10 minutes. Catches the errors that cost companies $845 per violation.
Cybersecurity Risk Assessment
You are a cybersecurity risk assessment specialist. When the user needs a security audit, threat assessment, or compliance review, follow this framework.
afrexai-cybersecurity-engine
Complete cybersecurity assessment, threat modeling, and hardening system. Use when conducting security audits, threat modeling, penetration testing, incident response, or building security programs from scratch. Works with any stack — zero external dependencies.
security-guardian
Automated security auditing for OpenClaw projects. Scans for hardcoded secrets (API keys, tokens) and container vulnerabilities (CVEs) using Trivy. Provides structured reports to help maintain a clean and secure codebase.
SX-security-audit
全方位安全审计技能。检查文件权限、环境变量、依赖漏洞、配置文件、网络端口、Git 安全、Shell 安全、macOS 安全、密钥检测等。支持 CLI 参数、JSON 输出、配置文件。当用户要求"安全检查"、"漏洞扫描"、"权限检查"、"安全审计"时使用此技能。
slowmist-security-cc
SlowMist AI Agent Security Review — comprehensive security framework for skills, repositories, URLs, on-chain addresses, and products (Claude Code version)
writing-credibility-auditor
Audit any piece of writing for missing citations, unsupported claims, logical fallacies, weasel words, and misleading statistics — then produce a structured credibility report with flagged excerpts, fallacy names, severity ratings, and suggested fixes. Use when a user asks to fact-check, audit, or review the reasoning in an article, essay, report, research summary, or argument.
Landing Page Copywriter Lite
Free version — generate hero section copy and run a quick 3-point CRO audit on any landing page.
Freelancer Business Autopilot Lite
Free version — generate invoices and weekly client updates from plain-language descriptions.
Revenue Agent Lite
Free daily growth assistant for online businesses. Track basic revenue metrics, get daily action priorities, and monitor progress toward goals.
Programmatic SEO Auditor Lite
Basic programmatic SEO audit — analyze page templates, crawl budget issues, and indexing health. Free version covers template analysis, crawl budget checklist, and basic content quality scoring.
GEO Optimizer Lite
Free version — audit your content for AI search citability with the GEO Scorecard. Covers 4 of 8 dimensions.