skill-audit-mcp

MCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.

사용해야 할까요

품질 및 안전성

A
설명 품질
100%
스키마 완전성
93%
이름 품질
87%
오염 위험
100%
권한 일치
100%
프로토콜 준수
100%

도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.

컨텍스트 비용

~1,288토큰 (도구 정의)
~520 B일반적인 응답 크기
중간 정도의 주의 영향 (128k 컨텍스트의 1.01%)

이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.

설치

원클릭 설치

`claude_desktop_config.json` 파일에 다음을 추가하세요:

{
  "mcpServers": {
    "skill-audit-mcp": {
      "url": "https://eltociear-skill-audit.hf.space/mcp"
    }
  }
}

원격 엔드포인트

https://eltociear-skill-audit.hf.space/mcpstreamable-http

할 수 있는 일

도구 목록

도구 (11)

🟢 읽기 전용🟡 쓰기🔴 삭제⚪ 알 수 없음
🟢paid_catalogue

List the paid API routes this same server offers, with prices and which ones need no input. The MCP tools here are free and general-purpose; the paid routes are specialised (on-chain token safety, live DEX prices, wallet intel, supply-chain scans). Payment is x402 over USDC on Base — no account or API key. Takes no arguments.

입력 스키마

{
  "type": "object",
  "properties": {},
  "required": []
}
⚪air_quality(location)

Current air quality for a place: PM2.5, PM10, ozone, NO2, SO2, CO and dust, plus the US and European AQI and the US AQI band ('Good', 'Unhealthy'). Takes a place name — no coordinates needed. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

입력 스키마

{
  "type": "object",
  "properties": {
    "location": {
      "type": "string",
      "description": "Place name, e.g. 'Tokyo'"
    }
  },
  "required": [
    "location"
  ]
}
⚪geocode(name, count)

Resolve a place name to coordinates, country, admin region, timezone, elevation and population. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

입력 스키마

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "description": "Place name to resolve"
    },
    "count": {
      "type": "integer",
      "description": "1-20 candidates (default 5)"
    }
  },
  "required": [
    "name"
  ]
}
⚪earthquakes(min_magnitude, days, limit, location, radius_km)

Recent earthquakes from the USGS feed — worldwide, or within a radius of a named place. Returns magnitude, depth, tsunami flag and felt reports. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

입력 스키마

{
  "type": "object",
  "properties": {
    "min_magnitude": {
      "type": "number",
      "description": "Lower bound (default 4.5)"
    },
    "days": {
      "type": "integer",
      "description": "1-30 days back (default 1)"
    },
    "limit": {
      "type": "integer",
      "description": "1-100 events (default 20)"
    },
    "location": {
      "type": "string",
      "description": "Centre on a place name"
    },
    "radius_km": {
      "type": "number",
      "description": "Radius around location (default 500)"
    }
  },
  "required": []
}
⚪public_holidays(country, year)

Public holidays for a country and year, with local names and a past/upcoming flag. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

입력 스키마

{
  "type": "object",
  "properties": {
    "country": {
      "type": "string",
      "description": "ISO 2-letter country code, e.g. JP"
    },
    "year": {
      "type": "integer",
      "description": "Calendar year (defaults to current)"
    }
  },
  "required": [
    "country"
  ]
}
⚪country_indicator(country, indicator, years)

World Bank time series for a country: gdp, gdp_per_capita, population, inflation, unemployment, life_expectancy, co2_per_capita or internet_users. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

입력 스키마

{
  "type": "object",
  "properties": {
    "country": {
      "type": "string",
      "description": "ISO 2- or 3-letter country code"
    },
    "indicator": {
      "type": "string",
      "description": "Alias above, or a World Bank code"
    },
    "years": {
      "type": "integer",
      "description": "1-60 most recent years (default 5)"
    }
  },
  "required": [
    "country"
  ]
}
⚪elevation(location)

Ground elevation in metres for a place name. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

입력 스키마

{
  "type": "object",
  "properties": {
    "location": {
      "type": "string",
      "description": "Place name"
    }
  },
  "required": [
    "location"
  ]
}
🟢web_search(query, max_results)

Search the live web and return ranked title/url/snippet results, through an automatic multi-engine failover chain. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

입력 스키마

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "Search query"
    },
    "max_results": {
      "type": "integer",
      "description": "1-25 (default 10)"
    }
  },
  "required": [
    "query"
  ]
}
🟢read_url(url)

Fetch a URL and return its main content as clean Markdown, boilerplate stripped. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

입력 스키마

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Page to fetch"
    }
  },
  "required": [
    "url"
  ]
}
🟢audit_skill_text(content)

Scan text — an agent skill, MCP server source, or plugin — for malicious behaviour before loading it. 17 attack patterns / 59 regex signatures across 4 severity levels — credential exfiltration, download-and-execute, prompt injection, command execution, seed-phrase harvesting and more.

입력 스키마

{
  "type": "object",
  "properties": {
    "content": {
      "type": "string",
      "description": "File or snippet to scan"
    }
  },
  "required": [
    "content"
  ]
}
🟢audit_skill_url(url)

Fetch a URL and scan what it serves for malicious behaviour. 17 attack patterns / 59 regex signatures across 4 severity levels — credential exfiltration, download-and-execute, prompt injection, command execution, seed-phrase harvesting and more.

입력 스키마

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Raw file URL to fetch and scan"
    }
  },
  "required": [
    "url"
  ]
}

커뮤니티

이 서버 평가하기

증거

최근 관측

검증됨버전이 기록되지 않음도구 11개
검증됨버전이 기록되지 않음도구 11개