skill-audit-mcp
MCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.
使うべきか
品質と安全性
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"skill-audit-mcp": {
"url": "https://eltociear-skill-audit.hf.space/mcp"
}
}
}リモートエンドポイント
https://eltociear-skill-audit.hf.space/mcpstreamable-httpできること
ツール一覧
ツール(11)
🟢paid_catalogue
List the paid API routes this same server offers, with prices and which ones need no input. The MCP tools here are free and general-purpose; the paid routes are specialised (on-chain token safety, live DEX prices, wallet intel, supply-chain scans). Payment is x402 over USDC on Base — no account or API key. Takes no arguments.
入力スキーマ
{
"type": "object",
"properties": {},
"required": []
}⚪air_quality(location)
Current air quality for a place: PM2.5, PM10, ozone, NO2, SO2, CO and dust, plus the US and European AQI and the US AQI band ('Good', 'Unhealthy'). Takes a place name — no coordinates needed. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
入力スキーマ
{
"type": "object",
"properties": {
"location": {
"type": "string",
"description": "Place name, e.g. 'Tokyo'"
}
},
"required": [
"location"
]
}⚪geocode(name, count)
Resolve a place name to coordinates, country, admin region, timezone, elevation and population. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
入力スキーマ
{
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "Place name to resolve"
},
"count": {
"type": "integer",
"description": "1-20 candidates (default 5)"
}
},
"required": [
"name"
]
}⚪earthquakes(min_magnitude, days, limit, location, radius_km)
Recent earthquakes from the USGS feed — worldwide, or within a radius of a named place. Returns magnitude, depth, tsunami flag and felt reports. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
入力スキーマ
{
"type": "object",
"properties": {
"min_magnitude": {
"type": "number",
"description": "Lower bound (default 4.5)"
},
"days": {
"type": "integer",
"description": "1-30 days back (default 1)"
},
"limit": {
"type": "integer",
"description": "1-100 events (default 20)"
},
"location": {
"type": "string",
"description": "Centre on a place name"
},
"radius_km": {
"type": "number",
"description": "Radius around location (default 500)"
}
},
"required": []
}⚪public_holidays(country, year)
Public holidays for a country and year, with local names and a past/upcoming flag. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
入力スキーマ
{
"type": "object",
"properties": {
"country": {
"type": "string",
"description": "ISO 2-letter country code, e.g. JP"
},
"year": {
"type": "integer",
"description": "Calendar year (defaults to current)"
}
},
"required": [
"country"
]
}⚪country_indicator(country, indicator, years)
World Bank time series for a country: gdp, gdp_per_capita, population, inflation, unemployment, life_expectancy, co2_per_capita or internet_users. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
入力スキーマ
{
"type": "object",
"properties": {
"country": {
"type": "string",
"description": "ISO 2- or 3-letter country code"
},
"indicator": {
"type": "string",
"description": "Alias above, or a World Bank code"
},
"years": {
"type": "integer",
"description": "1-60 most recent years (default 5)"
}
},
"required": [
"country"
]
}⚪elevation(location)
Ground elevation in metres for a place name. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
入力スキーマ
{
"type": "object",
"properties": {
"location": {
"type": "string",
"description": "Place name"
}
},
"required": [
"location"
]
}🟢web_search(query, max_results)
Search the live web and return ranked title/url/snippet results, through an automatic multi-engine failover chain. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
入力スキーマ
{
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "Search query"
},
"max_results": {
"type": "integer",
"description": "1-25 (default 10)"
}
},
"required": [
"query"
]
}🟢read_url(url)
Fetch a URL and return its main content as clean Markdown, boilerplate stripped. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
入力スキーマ
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "Page to fetch"
}
},
"required": [
"url"
]
}🟢audit_skill_text(content)
Scan text — an agent skill, MCP server source, or plugin — for malicious behaviour before loading it. 17 attack patterns / 65 regex signatures across 4 severity levels — credential exfiltration, download-and-execute, prompt injection, command execution, seed-phrase harvesting and more.
入力スキーマ
{
"type": "object",
"properties": {
"content": {
"type": "string",
"description": "File or snippet to scan"
}
},
"required": [
"content"
]
}🟢audit_skill_url(url)
Fetch a URL and scan what it serves for malicious behaviour. 17 attack patterns / 65 regex signatures across 4 severity levels — credential exfiltration, download-and-execute, prompt injection, command execution, seed-phrase harvesting and more.
入力スキーマ
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "Raw file URL to fetch and scan"
}
},
"required": [
"url"
]
}コミュニティ
エビデンス