skill-audit-mcp
MCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.
사용해야 할까요
품질 및 안전성
도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.
컨텍스트 비용
이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.
설치
원클릭 설치
`claude_desktop_config.json` 파일에 다음을 추가하세요:
{
"mcpServers": {
"skill-audit-mcp": {
"url": "https://eltociear-skill-audit.hf.space/mcp"
}
}
}원격 엔드포인트
https://eltociear-skill-audit.hf.space/mcpstreamable-http할 수 있는 일
도구 목록
도구 (11)
🟢paid_catalogue
List the paid API routes this same server offers, with prices and which ones need no input. The MCP tools here are free and general-purpose; the paid routes are specialised (on-chain token safety, live DEX prices, wallet intel, supply-chain scans). Payment is x402 over USDC on Base — no account or API key. Takes no arguments.
입력 스키마
{
"type": "object",
"properties": {},
"required": []
}⚪air_quality(location)
Current air quality for a place: PM2.5, PM10, ozone, NO2, SO2, CO and dust, plus the US and European AQI and the US AQI band ('Good', 'Unhealthy'). Takes a place name — no coordinates needed. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
입력 스키마
{
"type": "object",
"properties": {
"location": {
"type": "string",
"description": "Place name, e.g. 'Tokyo'"
}
},
"required": [
"location"
]
}⚪geocode(name, count)
Resolve a place name to coordinates, country, admin region, timezone, elevation and population. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
입력 스키마
{
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "Place name to resolve"
},
"count": {
"type": "integer",
"description": "1-20 candidates (default 5)"
}
},
"required": [
"name"
]
}⚪earthquakes(min_magnitude, days, limit, location, radius_km)
Recent earthquakes from the USGS feed — worldwide, or within a radius of a named place. Returns magnitude, depth, tsunami flag and felt reports. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
입력 스키마
{
"type": "object",
"properties": {
"min_magnitude": {
"type": "number",
"description": "Lower bound (default 4.5)"
},
"days": {
"type": "integer",
"description": "1-30 days back (default 1)"
},
"limit": {
"type": "integer",
"description": "1-100 events (default 20)"
},
"location": {
"type": "string",
"description": "Centre on a place name"
},
"radius_km": {
"type": "number",
"description": "Radius around location (default 500)"
}
},
"required": []
}⚪public_holidays(country, year)
Public holidays for a country and year, with local names and a past/upcoming flag. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
입력 스키마
{
"type": "object",
"properties": {
"country": {
"type": "string",
"description": "ISO 2-letter country code, e.g. JP"
},
"year": {
"type": "integer",
"description": "Calendar year (defaults to current)"
}
},
"required": [
"country"
]
}⚪country_indicator(country, indicator, years)
World Bank time series for a country: gdp, gdp_per_capita, population, inflation, unemployment, life_expectancy, co2_per_capita or internet_users. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
입력 스키마
{
"type": "object",
"properties": {
"country": {
"type": "string",
"description": "ISO 2- or 3-letter country code"
},
"indicator": {
"type": "string",
"description": "Alias above, or a World Bank code"
},
"years": {
"type": "integer",
"description": "1-60 most recent years (default 5)"
}
},
"required": [
"country"
]
}⚪elevation(location)
Ground elevation in metres for a place name. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
입력 스키마
{
"type": "object",
"properties": {
"location": {
"type": "string",
"description": "Place name"
}
},
"required": [
"location"
]
}🟢web_search(query, max_results)
Search the live web and return ranked title/url/snippet results, through an automatic multi-engine failover chain. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
입력 스키마
{
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "Search query"
},
"max_results": {
"type": "integer",
"description": "1-25 (default 10)"
}
},
"required": [
"query"
]
}🟢read_url(url)
Fetch a URL and return its main content as clean Markdown, boilerplate stripped. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
입력 스키마
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "Page to fetch"
}
},
"required": [
"url"
]
}🟢audit_skill_text(content)
Scan text — an agent skill, MCP server source, or plugin — for malicious behaviour before loading it. 17 attack patterns / 59 regex signatures across 4 severity levels — credential exfiltration, download-and-execute, prompt injection, command execution, seed-phrase harvesting and more.
입력 스키마
{
"type": "object",
"properties": {
"content": {
"type": "string",
"description": "File or snippet to scan"
}
},
"required": [
"content"
]
}🟢audit_skill_url(url)
Fetch a URL and scan what it serves for malicious behaviour. 17 attack patterns / 59 regex signatures across 4 severity levels — credential exfiltration, download-and-execute, prompt injection, command execution, seed-phrase harvesting and more.
입력 스키마
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "Raw file URL to fetch and scan"
}
},
"required": [
"url"
]
}커뮤니티
증거