
skill-audit-mcp
MCP server by github.com/eltociear/skill-audit-mcp
MCP server: static security scanner for MCP servers, agent skills & plugins. 68 attack patterns.
About skill-audit-mcp
skill-audit-mcp is an MCP (Model Context Protocol) server published by eltociear in the official MCP registry, listed under Security on Loomal. MCP server: static security scanner for MCP servers, agent skills & plugins. 68 attack patterns.
It ships as a Docker image (ghcr.io/eltociear/skill-audit-mcp:mcp-1.0.2), so any MCP client that can launch a local process can run it.
Development happens in the open at github.com/eltociear/skill-audit-mcp, where the project has earned 3 GitHub stars.
Use skill-audit-mcp with your agent
claude mcp add skill-audit-mcp -- docker run -i --rm ghcr.io/eltociear/skill-audit-mcp:mcp-1.0.2{
"mcpServers": {
"skill-audit-mcp": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/eltociear/skill-audit-mcp:mcp-1.0.2"
]
}
}
}ghcr.io/eltociear/skill-audit-mcp:mcp-1.0.2Frequently asked questions
- What is skill-audit-mcp?
- skill-audit-mcp is an MCP (Model Context Protocol) server by eltociear in the Security category. MCP server: static security scanner for MCP servers, agent skills & plugins. 68 attack patterns.
- How do I connect skill-audit-mcp to Claude, Cursor, or another MCP client?
- Install skill-audit-mcp from its oci package (ghcr.io/eltociear/skill-audit-mcp:mcp-1.0.2) and register it under "mcpServers" in your client's MCP configuration — for example claude_desktop_config.json or Cursor's mcp.json — then restart the client.
- Is skill-audit-mcp open source?
- Yes — the source code is public at github.com/eltociear/skill-audit-mcp, with 3 GitHub stars.
- Can AI agents pay to use skill-audit-mcp?
- Not yet through Loomal — skill-audit-mcp is listed as a free directory entry. If its maintainer verifies ownership, they can set per-call USDC pricing that agents pay over x402, with settlement on Base.
More Security MCP servers

idea-reality-mcp
719
Pre-build reality check. Scans GitHub, HN, npm, PyPI, Product Hunt — returns 0-100 signal.

skylos
453
Dead code, security, secrets detection and code quality for Python, TypeScript, Go.

MCPProxy
253
Local-first MCP proxy with BM25 tool discovery, security scanning, quarantine & ~99% token savings

mcp-afip
252
AFIP — Argentine tax authority, electronic invoicing (Factura Electrónica)

mcp-ap2
252
MCP server for AP2 — Google's Agent-to-Agent Payment Protocol (authorization, audit, trust)

OpenClaw MCP Server
172
MCP server bridging Claude.ai/Desktop with self-hosted OpenClaw via OAuth 2.1.
Listing data from the official MCP registry and GitHub, refreshed periodically. Not affiliated with the maintainer unless claimed. Maintain skill-audit-mcp? Claim this listing free by verifying GitHub ownership, or contact us.