
Agent Skill & Config Security Audit
io.github.tylerscomic-labv1.0.0更新于 Oct 2, 2026
Scan AI agent skills and configs for hidden Unicode, prompt injection and exfiltration.
概览
在安装前扫描 AI 智能体技能与配置文件,查找隐藏 Unicode、提示注入、数据外泄模式和过宽权限。
- 功能
- 该服务器对智能体指令与配置文件(如 SKILL.md、CLAUDE.md、AGENTS.md、.cursorrules、.mcp.json 和 settings.json)进行静态安全分析。audit_skill_file 工具扫描技能文件及随附脚本,audit_agent_config 审计智能体配置文件,reveal_hidden_text 可查找并解码任意文本中的不可见字符并返回清理后的副本。它会报告隐藏的 Unicode 指令、提示注入语句、下载并执行与混淆模式、外泄特征,以及有风险的权限或配置设置。
- 适用场景
- 当你即将安装或信任第三方智能体技能、指令文件或 MCP 配置,并希望快速检查其中是否含有隐藏指令、注入文本、外泄命令或过宽权限时使用。它也适合审查并非由你编写的随附脚本和配置文件。
- 运行要求
- 提供远程 streamable HTTP 端点;README 说明其托管在 MCPize 上,有每天 10 次调用的免费额度,并使用来自 MCPize 的 API 密钥。也可用 Node.js 在本地运行,通过 npm install 和 node server.js 启动,监听 8080 端口,MCP 路径为 /mcp。清单中未声明任何环境变量或请求头。
安装
在 SourceWeft 中
- 打开 控制台中的 Agent Skill & Config Security Audit,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"agent-skill-audit-mcp": {
"type": "http",
"url": "https://agent-skill-audit-mcp.mcpize.run/mcp"
}
}
}README
Agent Skill & Config Security Audit
Security scanner for AI agent skills and config files (SKILL.md, CLAUDE.md, AGENTS.md, .mcp.json, settings.json). Finds hidden Unicode instructions, prompt injection, exfiltration commands and over-broad permissions before you install a skill.
Scan a skill before you install it
Agent skills and instruction files are read straight into your agent's context, and some ship scripts it can run. Research on public skill registries has found prompt injection and credential-stealing payloads in a large share of them. Installing a third-party skill is closer to adding a dependency than opening a document, and nothing scans them. This does.
What it catches
- Hidden Unicode instructions: invisible "tag" characters that render as blank but that models can read, plus zero-width and bidi control characters. The hidden message is decoded for you.
- Prompt injection: "ignore previous instructions", "do not tell the user", fake system messages, approval bypasses.
- Download-and-execute and obfuscation:
curl | bash, base64-decode-and-run, large encoded blobs. - Exfiltration shapes: network commands that reference env vars or credential files, request-catcher and tunnel hosts, sensitive paths like
~/.sshand.aws/credentials. - Over-broad permissions: unrestricted
Bashin allowed-tools,Bash(*)pre-approvals, bypassed permissions. - Risky agent configs: unpinned
@latestMCP servers, inline secrets, plaintext remote servers, hooks that make network calls, API base-URL overrides, auto-trusted project MCP servers.
Tools
audit_skill_file: scan SKILL.md, CLAUDE.md, AGENTS.md, .cursorrules or a bundled script.audit_agent_config: audit .mcp.json or .claude/settings.json.reveal_hidden_text: find and decode invisible characters in any text, and return a cleaned copy.
Static analysis only. Nothing in your input is executed or fetched. A clean result is not a guarantee, so read bundled scripts too.
Use it
Hosted on MCPize with a free tier (10 calls a day). Remote MCP endpoint (streamable HTTP, API key from MCPize):
Or run it yourself:
MIT licensed.
来源:README.md,提交 9dc333f
工具
0版本历史
1- v1.0.0最新Oct 2, 2026