Skill Audit MCP

Cross-referenced from the discovery channels that AI/security engineers actually read. It is available as a remote MCP endpoint.

Teams that want a hosted security endpoint instead of running a local process. The project is written in Python.

VERIFIED ACTIVE

LAST COMMIT 2026-08-19 · ★ 5 · #143 OF 182 MAINTAINED SECURITY · VERIFIED 2026-08-25

Python servers · how we verify → /methodology

01 · Install Skill Audit MCP

Claude Code

claude mcp add eltociear-skill-audit-mcp --transport http https://eltociear-skill-audit.hf.space/mcp

Claude Desktop / Cursor / VS Code - add to config

{
  "mcpServers": {
    "eltociear-skill-audit-mcp": {
      "url": "https://eltociear-skill-audit.hf.space/mcp"
    }
  }
}

Same JSON for Cursor. For VS Code, rename the top-level key from `mcpServers` to `servers`.

Using another client? Same JSON, different key

Claude Desktop · mcpServers

Cursor · mcpServers

VS Code · servers

Windsurf · mcpServers

Zed · context_servers

Cline · mcpServers

Roo Code · mcpServers

Continue · mcpServers

LibreChat · mcpServers

Gemini CLI · mcpServers

Codex CLI · mcp_servers

Full setup guides: every client.

02 · Evidence

https://eltociear-skill-audit.hf.space/mcp

transport: streamable-http

endpoint alive - responded to MCP initialize · probed 2026-08-25

Security posture

What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.

runs as remote - your agent's requests go to eltociear-skill-audit.hf.space

endpoint auth accepted our unauthenticated MCP initialize - no credentials needed to connect

license no standard license detected - usage rights unclear; check the repo before commercial use

registry namespace io.github.eltociear is GitHub-verified and matches the repo owner

03 · What Skill Audit MCP can do

Prose above is summarized from the project's README and registry record - no invented capabilities.

Latest releases

v1.0.1 · 2026-05-11

Adds Cline marketplace approval requirements and broadens distribution: · llms-install.md: explicit LLM-driven install instructions · SECURITY.md: vulnerability reporting policy · alpine-based scanner image…

v1.0.0 · 2026-04-30

Scan MCP servers, AI agent skills, and plugins for 68+ malicious patterns. · Credential exfiltration · Prompt injection · Code execution · Seed phrase harvesting · Download & execute · Identity impersonation · Add to…

04 · Who maintains Skill Audit MCP

skill-audit-mcp is maintained by eltociear. We track 4 MCP servers from eltociear - 4 actively maintained, 8 combined GitHub stars, oldest repo from Apr 2026.

05 · Facts

category
security - ranked #143 of 182 actively-maintained security servers as of 2026-08-25.
registry
io.github.eltociear/skill-audit-mcp (active, first published 2026-06-07 · 2 versions)

06 · Skill Audit MCP FAQ

What is Skill Audit MCP?

Cross-referenced from the discovery channels that AI/security engineers actually read. It is available as a remote MCP endpoint.

Is Skill Audit MCP still maintained?

Yes - as of 2026-08-25, its last commit was 2026-08-19. We re-verify nightly.

How do I install Skill Audit MCP?

Run `claude mcp add eltociear-skill-audit-mcp --transport http https://eltociear-skill-audit.hf.space/mcp`. You can also paste the ready-made client config above.

Does Skill Audit MCP require authentication?

No - the endpoint accepted our unauthenticated MCP initialize when probed on 2026-08-25; you can connect without credentials.

07 · Alternatives to Skill Audit MCP

More security MCP servers · Sanction · Haldir · Flagrix · Clover Public · Zendesk MCP Server

More Python MCP servers · Memory Fabric · Emercoin Agent · Semahash · Blender Optics Simulator · Evc Team Relay MCP · see all