🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

skillssafe-mcp

Package Overview
Dependencies
Maintainers
1
Versions
2
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

skillssafe-mcp

MCP server for SkillsSafe — AI agent skill security scanner. Detects prompt injection, credential theft, zero-width character attacks, and ClawHavoc malware. Free, no API key required.

latest
Source
npmnpm
Version
1.1.0
Version published
Weekly downloads
44
10%
Maintainers
1
Weekly downloads
 
Created
Source

skillssafe-mcp

npm version MCP Registry License: MIT

MCP server for SkillsSafe — the security layer for AI agents.

Scan SKILL.md files, MCP configs, and system prompts for:

  • 🔐 Credential theft & data exfiltration
  • 💉 Prompt injection attacks
  • 👻 Zero-width character attacks
  • 🦠 ClawHavoc malware indicators
  • 🐚 Shell injection & reverse shells
  • 🔍 Scope creep & memory poisoning

Free. No API key. No signup.

Quick Start

Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "skillssafe": {
      "command": "npx",
      "args": ["-y", "skillssafe-mcp"]
    }
  }
}

Cursor

Add to .cursor/mcp.json:

{
  "mcpServers": {
    "skillssafe": {
      "command": "npx",
      "args": ["-y", "skillssafe-mcp"]
    }
  }
}

Direct SSE (Remote)

For clients that support SSE transport:

https://mcp.skillssafe.com/sse

Tools

scan_skill

Scan an AI agent skill file for security threats before installation.

Parameters:
  url      - URL of skill to scan (GitHub raw URL, ClawHub URL, etc.)
  content  - Raw text content of skill to scan (alternative to url)
  lang     - Response language: "en" | "zh" | "ja" (default: "en")

Returns:
  decision    - INSTALL / REVIEW / BLOCK
  risk_score  - 0–100
  threats     - List of detected threats with severity
  scan_id     - ID for retrieving full report

get_report

Retrieve a previously generated scan report.

Parameters:
  scan_id  - Scan ID returned by scan_skill

Registry

🛡️ Security Audit

This project is indexed by SkillsSafe.

You can audit this MCP server before installing it:

openclaw mcp add skillssafe https://mcp.skillssafe.com/sse

Check out the community discussion on Cursor Forum.

License

MIT © SkillsSafe

Keywords

mcp

FAQs

Package last updated on 12 Mar 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts