Agent Skill & Config Security Audit

io.github.tylerscomic-labv1.0.0更新于 Oct 2, 2026

Scan AI agent skills and configs for hidden Unicode, prompt injection and exfiltration.

已验证Streamable HTTP可网页运行Developer ToolsSecurity & Monitoring

概览

AI 生成的概览

在安装前扫描 AI 智能体技能与配置文件,查找隐藏 Unicode、提示注入、数据外泄模式和过宽权限。

功能
该服务器对智能体指令与配置文件(如 SKILL.md、CLAUDE.md、AGENTS.md、.cursorrules、.mcp.json 和 settings.json)进行静态安全分析。audit_skill_file 工具扫描技能文件及随附脚本,audit_agent_config 审计智能体配置文件,reveal_hidden_text 可查找并解码任意文本中的不可见字符并返回清理后的副本。它会报告隐藏的 Unicode 指令、提示注入语句、下载并执行与混淆模式、外泄特征,以及有风险的权限或配置设置。
适用场景
当你即将安装或信任第三方智能体技能、指令文件或 MCP 配置,并希望快速检查其中是否含有隐藏指令、注入文本、外泄命令或过宽权限时使用。它也适合审查并非由你编写的随附脚本和配置文件。
运行要求
提供远程 streamable HTTP 端点;README 说明其托管在 MCPize 上,有每天 10 次调用的免费额度,并使用来自 MCPize 的 API 密钥。也可用 Node.js 在本地运行,通过 npm install 和 node server.js 启动,监听 8080 端口,MCP 路径为 /mcp。清单中未声明任何环境变量或请求头。
安装前请注意
README 说明分析仅为静态,输入内容不会被运行或抓取,且干净的结果并不构成保证,因此仍应阅读随附脚本。托管端点需要来自 MCPize 的 API 密钥,免费额度限制为每天 10 次调用。你提交的文件会被发送到远程服务进行扫描。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Agent Skill & Config Security Audit,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。

其他 MCP 客户端

把它添加到你客户端的 mcpServers 配置中。

{
  "mcpServers": {
    "agent-skill-audit-mcp": {
      "type": "http",
      "url": "https://agent-skill-audit-mcp.mcpize.run/mcp"
    }
  }
}

README

Agent Skill & Config Security Audit

Security scanner for AI agent skills and config files (SKILL.md, CLAUDE.md, AGENTS.md, .mcp.json, settings.json). Finds hidden Unicode instructions, prompt injection, exfiltration commands and over-broad permissions before you install a skill.

Scan a skill before you install it

Agent skills and instruction files are read straight into your agent's context, and some ship scripts it can run. Research on public skill registries has found prompt injection and credential-stealing payloads in a large share of them. Installing a third-party skill is closer to adding a dependency than opening a document, and nothing scans them. This does.

What it catches

  • Hidden Unicode instructions: invisible "tag" characters that render as blank but that models can read, plus zero-width and bidi control characters. The hidden message is decoded for you.
  • Prompt injection: "ignore previous instructions", "do not tell the user", fake system messages, approval bypasses.
  • Download-and-execute and obfuscation: curl | bash, base64-decode-and-run, large encoded blobs.
  • Exfiltration shapes: network commands that reference env vars or credential files, request-catcher and tunnel hosts, sensitive paths like ~/.ssh and .aws/credentials.
  • Over-broad permissions: unrestricted Bash in allowed-tools, Bash(*) pre-approvals, bypassed permissions.
  • Risky agent configs: unpinned @latest MCP servers, inline secrets, plaintext remote servers, hooks that make network calls, API base-URL overrides, auto-trusted project MCP servers.

Tools

  • audit_skill_file: scan SKILL.md, CLAUDE.md, AGENTS.md, .cursorrules or a bundled script.
  • audit_agent_config: audit .mcp.json or .claude/settings.json.
  • reveal_hidden_text: find and decode invisible characters in any text, and return a cleaned copy.

Static analysis only. Nothing in your input is executed or fetched. A clean result is not a guarantee, so read bundled scripts too.

Use it

Hosted on MCPize with a free tier (10 calls a day). Remote MCP endpoint (streamable HTTP, API key from MCPize):

https://agent-skill-audit-mcp.mcpize.run/mcp

Or run it yourself:

bash
npm installnode server.js   # listens on :8080, MCP at /mcp

MIT licensed.

来源:README.md,提交 9dc333f

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.0.0最新Oct 2, 2026