Skip to content

Add skill-audit-mcp to Security#793

Open
eltociear wants to merge 1 commit into
sdras:mainfrom
eltociear:add-skill-audit-mcp
Open

Add skill-audit-mcp to Security#793
eltociear wants to merge 1 commit into
sdras:mainfrom
eltociear:add-skill-audit-mcp

Conversation

@eltociear
Copy link
Copy Markdown

Adds skill-audit-mcp under Security.

Scans MCP servers, AI agent skill files, and plugins for 68 attack patterns across 4 severity levels:

  • CRITICAL — credential exfiltration, seed-phrase harvest, download-and-execute
  • HIGH — arbitrary code execution, auth bypass, identity impersonation
  • MEDIUM — prompt injection, obfuscation, privilege escalation
  • LOW — external URL refs, broad filesystem access

Output: SARIF 2.1.0 → GitHub Code Scanning Security tab.

Usage:

- uses: eltociear/skill-audit-mcp@v1
  with:
    path: '.'
    severity: 'MEDIUM'
    fail-on: 'HIGH'

Composite action, no Docker/Node setup overhead. Released v1.0.1 on 2026-05-11.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants