Agent Skill & Config Security Audit

io.github.tylerscomic-labv1.0.0Updated Oct 2, 2026

Scan AI agent skills and configs for hidden Unicode, prompt injection and exfiltration.

VerifiedStreamable HTTPWeb executableDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Scans AI agent skill and config files for hidden Unicode, prompt injection, exfiltration patterns and over-broad permissions before installation.

What it does
This server performs static security analysis of agent instruction and configuration files such as SKILL.md, CLAUDE.md, AGENTS.md, .cursorrules, .mcp.json and settings.json. Its audit_skill_file tool scans skill files and bundled scripts, audit_agent_config audits agent configuration files, and reveal_hidden_text finds and decodes invisible characters in any text and returns a cleaned copy. It reports hidden Unicode instructions, prompt injection phrases, download-and-execute and obfuscation patterns, exfiltration shapes, and risky permission or config settings.
When to use it
Use it when you are about to install or trust a third-party agent skill, instruction file or MCP configuration and want a quick check for hidden instructions, injection text, exfiltration commands or overly broad permissions. It is also useful for reviewing bundled scripts and config files you did not write yourself.
Requirements
A remote streamable HTTP endpoint is provided; the README states it is hosted on MCPize with a free tier of 10 calls a day and that an API key from MCPize is used. It can alternatively be run locally with Node.js via npm install and node server.js, listening on port 8080 with MCP at /mcp. No environment variables or headers are declared in the manifest.
Before you install
The README states analysis is static only and that nothing in the input is executed or fetched, and that a clean result is not a guarantee, so bundled scripts should still be read. The hosted endpoint requires an API key from MCPize, and the free tier is limited to 10 calls a day. Files you submit are sent to the remote service for scanning.

Installation

In SourceWeft

  1. Open Agent Skill & Config Security Audit in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "agent-skill-audit-mcp": {
      "type": "http",
      "url": "https://agent-skill-audit-mcp.mcpize.run/mcp"
    }
  }
}

README

Agent Skill & Config Security Audit

Security scanner for AI agent skills and config files (SKILL.md, CLAUDE.md, AGENTS.md, .mcp.json, settings.json). Finds hidden Unicode instructions, prompt injection, exfiltration commands and over-broad permissions before you install a skill.

Scan a skill before you install it

Agent skills and instruction files are read straight into your agent's context, and some ship scripts it can run. Research on public skill registries has found prompt injection and credential-stealing payloads in a large share of them. Installing a third-party skill is closer to adding a dependency than opening a document, and nothing scans them. This does.

What it catches

  • Hidden Unicode instructions: invisible "tag" characters that render as blank but that models can read, plus zero-width and bidi control characters. The hidden message is decoded for you.
  • Prompt injection: "ignore previous instructions", "do not tell the user", fake system messages, approval bypasses.
  • Download-and-execute and obfuscation: curl | bash, base64-decode-and-run, large encoded blobs.
  • Exfiltration shapes: network commands that reference env vars or credential files, request-catcher and tunnel hosts, sensitive paths like ~/.ssh and .aws/credentials.
  • Over-broad permissions: unrestricted Bash in allowed-tools, Bash(*) pre-approvals, bypassed permissions.
  • Risky agent configs: unpinned @latest MCP servers, inline secrets, plaintext remote servers, hooks that make network calls, API base-URL overrides, auto-trusted project MCP servers.

Tools

  • audit_skill_file: scan SKILL.md, CLAUDE.md, AGENTS.md, .cursorrules or a bundled script.
  • audit_agent_config: audit .mcp.json or .claude/settings.json.
  • reveal_hidden_text: find and decode invisible characters in any text, and return a cleaned copy.

Static analysis only. Nothing in your input is executed or fetched. A clean result is not a guarantee, so read bundled scripts too.

Use it

Hosted on MCPize with a free tier (10 calls a day). Remote MCP endpoint (streamable HTTP, API key from MCPize):

https://agent-skill-audit-mcp.mcpize.run/mcp

Or run it yourself:

bash
npm installnode server.js   # listens on :8080, MCP at /mcp

MIT licensed.

Source: README.md at commit 9dc333f

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.0.0LatestOct 2, 2026