skill-audit-mcp
MCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.
Sollte ich dies verwenden
Qualität und Sicherheit
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"skill-audit-mcp": {
"url": "https://eltociear-skill-audit.hf.space/mcp"
}
}
}Remote-Endpunkte
https://eltociear-skill-audit.hf.space/mcpstreamable-httpWas es kann
Tool-Inventar
Tools (11)
🟢paid_catalogue
List the paid API routes this same server offers, with prices and which ones need no input. The MCP tools here are free and general-purpose; the paid routes are specialised (on-chain token safety, live DEX prices, wallet intel, supply-chain scans). Payment is x402 over USDC on Base — no account or API key. Takes no arguments.
Eingabe-Schema
{
"type": "object",
"properties": {},
"required": []
}⚪air_quality(location)
Current air quality for a place: PM2.5, PM10, ozone, NO2, SO2, CO and dust, plus the US and European AQI and the US AQI band ('Good', 'Unhealthy'). Takes a place name — no coordinates needed. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
Eingabe-Schema
{
"type": "object",
"properties": {
"location": {
"type": "string",
"description": "Place name, e.g. 'Tokyo'"
}
},
"required": [
"location"
]
}⚪geocode(name, count)
Resolve a place name to coordinates, country, admin region, timezone, elevation and population. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
Eingabe-Schema
{
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "Place name to resolve"
},
"count": {
"type": "integer",
"description": "1-20 candidates (default 5)"
}
},
"required": [
"name"
]
}⚪earthquakes(min_magnitude, days, limit, location, radius_km)
Recent earthquakes from the USGS feed — worldwide, or within a radius of a named place. Returns magnitude, depth, tsunami flag and felt reports. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
Eingabe-Schema
{
"type": "object",
"properties": {
"min_magnitude": {
"type": "number",
"description": "Lower bound (default 4.5)"
},
"days": {
"type": "integer",
"description": "1-30 days back (default 1)"
},
"limit": {
"type": "integer",
"description": "1-100 events (default 20)"
},
"location": {
"type": "string",
"description": "Centre on a place name"
},
"radius_km": {
"type": "number",
"description": "Radius around location (default 500)"
}
},
"required": []
}⚪public_holidays(country, year)
Public holidays for a country and year, with local names and a past/upcoming flag. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
Eingabe-Schema
{
"type": "object",
"properties": {
"country": {
"type": "string",
"description": "ISO 2-letter country code, e.g. JP"
},
"year": {
"type": "integer",
"description": "Calendar year (defaults to current)"
}
},
"required": [
"country"
]
}⚪country_indicator(country, indicator, years)
World Bank time series for a country: gdp, gdp_per_capita, population, inflation, unemployment, life_expectancy, co2_per_capita or internet_users. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
Eingabe-Schema
{
"type": "object",
"properties": {
"country": {
"type": "string",
"description": "ISO 2- or 3-letter country code"
},
"indicator": {
"type": "string",
"description": "Alias above, or a World Bank code"
},
"years": {
"type": "integer",
"description": "1-60 most recent years (default 5)"
}
},
"required": [
"country"
]
}⚪elevation(location)
Ground elevation in metres for a place name. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
Eingabe-Schema
{
"type": "object",
"properties": {
"location": {
"type": "string",
"description": "Place name"
}
},
"required": [
"location"
]
}🟢web_search(query, max_results)
Search the live web and return ranked title/url/snippet results, through an automatic multi-engine failover chain. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
Eingabe-Schema
{
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "Search query"
},
"max_results": {
"type": "integer",
"description": "1-25 (default 10)"
}
},
"required": [
"query"
]
}🟢read_url(url)
Fetch a URL and return its main content as clean Markdown, boilerplate stripped. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
Eingabe-Schema
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "Page to fetch"
}
},
"required": [
"url"
]
}🟢audit_skill_text(content)
Scan text — an agent skill, MCP server source, or plugin — for malicious behaviour before loading it. 17 attack patterns / 59 regex signatures across 4 severity levels — credential exfiltration, download-and-execute, prompt injection, command execution, seed-phrase harvesting and more.
Eingabe-Schema
{
"type": "object",
"properties": {
"content": {
"type": "string",
"description": "File or snippet to scan"
}
},
"required": [
"content"
]
}🟢audit_skill_url(url)
Fetch a URL and scan what it serves for malicious behaviour. 17 attack patterns / 59 regex signatures across 4 severity levels — credential exfiltration, download-and-execute, prompt injection, command execution, seed-phrase harvesting and more.
Eingabe-Schema
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "Raw file URL to fetch and scan"
}
},
"required": [
"url"
]
}Community
Nachweis