skill-audit-mcp

MCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.

Sollte ich dies verwenden

Qualität und Sicherheit

A
Qualität der Beschreibung
100%
Vollständigkeit des Schemas
93%
Qualität der Benennung
87%
Risiko der Vergiftung
100%
Übereinstimmung der Berechtigungen
100%
Einhaltung des Protokolls
100%

Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.

Kontextkosten

~1,288Tokens (Tool-Definitionen)
~520 BTypische Antwortgröße
Mittlere Auswirkung auf die Aufmerksamkeit (1.01% von 128k Kontext)

Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.

Installieren

Installation mit einem Klick

Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:

{
  "mcpServers": {
    "skill-audit-mcp": {
      "url": "https://eltociear-skill-audit.hf.space/mcp"
    }
  }
}

Remote-Endpunkte

https://eltociear-skill-audit.hf.space/mcpstreamable-http

Was es kann

Tool-Inventar

Tools (11)

🟢 Nur lesen🟡 Schreiben🔴 Löschen⚪ Unbekannt
🟢paid_catalogue

List the paid API routes this same server offers, with prices and which ones need no input. The MCP tools here are free and general-purpose; the paid routes are specialised (on-chain token safety, live DEX prices, wallet intel, supply-chain scans). Payment is x402 over USDC on Base — no account or API key. Takes no arguments.

Eingabe-Schema

{
  "type": "object",
  "properties": {},
  "required": []
}
⚪air_quality(location)

Current air quality for a place: PM2.5, PM10, ozone, NO2, SO2, CO and dust, plus the US and European AQI and the US AQI band ('Good', 'Unhealthy'). Takes a place name — no coordinates needed. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "location": {
      "type": "string",
      "description": "Place name, e.g. 'Tokyo'"
    }
  },
  "required": [
    "location"
  ]
}
⚪geocode(name, count)

Resolve a place name to coordinates, country, admin region, timezone, elevation and population. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "description": "Place name to resolve"
    },
    "count": {
      "type": "integer",
      "description": "1-20 candidates (default 5)"
    }
  },
  "required": [
    "name"
  ]
}
⚪earthquakes(min_magnitude, days, limit, location, radius_km)

Recent earthquakes from the USGS feed — worldwide, or within a radius of a named place. Returns magnitude, depth, tsunami flag and felt reports. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "min_magnitude": {
      "type": "number",
      "description": "Lower bound (default 4.5)"
    },
    "days": {
      "type": "integer",
      "description": "1-30 days back (default 1)"
    },
    "limit": {
      "type": "integer",
      "description": "1-100 events (default 20)"
    },
    "location": {
      "type": "string",
      "description": "Centre on a place name"
    },
    "radius_km": {
      "type": "number",
      "description": "Radius around location (default 500)"
    }
  },
  "required": []
}
⚪public_holidays(country, year)

Public holidays for a country and year, with local names and a past/upcoming flag. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "country": {
      "type": "string",
      "description": "ISO 2-letter country code, e.g. JP"
    },
    "year": {
      "type": "integer",
      "description": "Calendar year (defaults to current)"
    }
  },
  "required": [
    "country"
  ]
}
⚪country_indicator(country, indicator, years)

World Bank time series for a country: gdp, gdp_per_capita, population, inflation, unemployment, life_expectancy, co2_per_capita or internet_users. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "country": {
      "type": "string",
      "description": "ISO 2- or 3-letter country code"
    },
    "indicator": {
      "type": "string",
      "description": "Alias above, or a World Bank code"
    },
    "years": {
      "type": "integer",
      "description": "1-60 most recent years (default 5)"
    }
  },
  "required": [
    "country"
  ]
}
⚪elevation(location)

Ground elevation in metres for a place name. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "location": {
      "type": "string",
      "description": "Place name"
    }
  },
  "required": [
    "location"
  ]
}
🟢web_search(query, max_results)

Search the live web and return ranked title/url/snippet results, through an automatic multi-engine failover chain. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "Search query"
    },
    "max_results": {
      "type": "integer",
      "description": "1-25 (default 10)"
    }
  },
  "required": [
    "query"
  ]
}
🟢read_url(url)

Fetch a URL and return its main content as clean Markdown, boilerplate stripped. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Page to fetch"
    }
  },
  "required": [
    "url"
  ]
}
🟢audit_skill_text(content)

Scan text — an agent skill, MCP server source, or plugin — for malicious behaviour before loading it. 17 attack patterns / 59 regex signatures across 4 severity levels — credential exfiltration, download-and-execute, prompt injection, command execution, seed-phrase harvesting and more.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "content": {
      "type": "string",
      "description": "File or snippet to scan"
    }
  },
  "required": [
    "content"
  ]
}
🟢audit_skill_url(url)

Fetch a URL and scan what it serves for malicious behaviour. 17 attack patterns / 59 regex signatures across 4 severity levels — credential exfiltration, download-and-execute, prompt injection, command execution, seed-phrase harvesting and more.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Raw file URL to fetch and scan"
    }
  },
  "required": [
    "url"
  ]
}

Community

Diesen Server bewerten

Nachweis

Aktuelle Beobachtungen

verifiziertVersion nicht aufgezeichnet11 Tools
verifiziertVersion nicht aufgezeichnet11 Tools