Agent Skill & Config Security Audit

io.github.tylerscomic-labv1.0.0更新於 Oct 2, 2026

Scan AI agent skills and configs for hidden Unicode, prompt injection and exfiltration.

已驗證Streamable HTTP可網頁執行Developer ToolsSecurity & Monitoring

概覽

AI 產生的概覽

在安裝前掃描 AI 代理技能與設定檔,找出隱藏 Unicode、提示注入、資料外洩模式與過寬權限。

功能
此伺服器對代理指令與設定檔(例如 SKILL.md、CLAUDE.md、AGENTS.md、.cursorrules、.mcp.json 與 settings.json)進行靜態安全分析。audit_skill_file 工具掃描技能檔案與隨附指令碼,audit_agent_config 稽核代理設定檔,reveal_hidden_text 可找出並解碼任意文字中的不可見字元,並回傳清理後的副本。它會回報隱藏的 Unicode 指令、提示注入語句、下載並執行與混淆模式、外洩特徵,以及有風險的權限或設定。
適用情境
當你即將安裝或信任第三方代理技能、指令檔或 MCP 設定,並想快速檢查其中是否含有隱藏指令、注入文字、外洩命令或過寬權限時使用。它也適合檢視並非由你撰寫的隨附指令碼與設定檔。
執行需求
提供遠端 streamable HTTP 端點;README 說明其託管於 MCPize,有每天 10 次呼叫的免費額度,並使用來自 MCPize 的 API 金鑰。也可用 Node.js 在本機執行,透過 npm install 與 node server.js 啟動,監聽 8080 埠,MCP 路徑為 /mcp。清單中未宣告任何環境變數或標頭。
安裝前請注意
README 說明分析僅為靜態,輸入內容不會被執行或抓取,且乾淨的結果並不構成保證,因此仍應閱讀隨附指令碼。託管端點需要來自 MCPize 的 API 金鑰,免費額度限制為每天 10 次呼叫。你提交的檔案會傳送到遠端服務進行掃描。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Agent Skill & Config Security Audit,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "agent-skill-audit-mcp": {
      "type": "http",
      "url": "https://agent-skill-audit-mcp.mcpize.run/mcp"
    }
  }
}

README

Agent Skill & Config Security Audit

Security scanner for AI agent skills and config files (SKILL.md, CLAUDE.md, AGENTS.md, .mcp.json, settings.json). Finds hidden Unicode instructions, prompt injection, exfiltration commands and over-broad permissions before you install a skill.

Scan a skill before you install it

Agent skills and instruction files are read straight into your agent's context, and some ship scripts it can run. Research on public skill registries has found prompt injection and credential-stealing payloads in a large share of them. Installing a third-party skill is closer to adding a dependency than opening a document, and nothing scans them. This does.

What it catches

  • Hidden Unicode instructions: invisible "tag" characters that render as blank but that models can read, plus zero-width and bidi control characters. The hidden message is decoded for you.
  • Prompt injection: "ignore previous instructions", "do not tell the user", fake system messages, approval bypasses.
  • Download-and-execute and obfuscation: curl | bash, base64-decode-and-run, large encoded blobs.
  • Exfiltration shapes: network commands that reference env vars or credential files, request-catcher and tunnel hosts, sensitive paths like ~/.ssh and .aws/credentials.
  • Over-broad permissions: unrestricted Bash in allowed-tools, Bash(*) pre-approvals, bypassed permissions.
  • Risky agent configs: unpinned @latest MCP servers, inline secrets, plaintext remote servers, hooks that make network calls, API base-URL overrides, auto-trusted project MCP servers.

Tools

  • audit_skill_file: scan SKILL.md, CLAUDE.md, AGENTS.md, .cursorrules or a bundled script.
  • audit_agent_config: audit .mcp.json or .claude/settings.json.
  • reveal_hidden_text: find and decode invisible characters in any text, and return a cleaned copy.

Static analysis only. Nothing in your input is executed or fetched. A clean result is not a guarantee, so read bundled scripts too.

Use it

Hosted on MCPize with a free tier (10 calls a day). Remote MCP endpoint (streamable HTTP, API key from MCPize):

https://agent-skill-audit-mcp.mcpize.run/mcp

Or run it yourself:

bash
npm installnode server.js   # listens on :8080, MCP at /mcp

MIT licensed.

來源:README.md,提交 9dc333f

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.0.0最新Oct 2, 2026