Skill Audit MCP
Cross-referenced from the discovery channels that AI/security engineers actually read. It is available as a remote MCP endpoint.
Teams that want a hosted security endpoint instead of running a local process. The project is written in Python.
VERIFIED ACTIVE
LAST COMMIT 2026-08-19 · ★ 5 · #143 OF 182 MAINTAINED SECURITY · VERIFIED 2026-08-25
Python servers · how we verify → /methodology
01 · Install Skill Audit MCP
Claude Code
claude mcp add eltociear-skill-audit-mcp --transport http https://eltociear-skill-audit.hf.space/mcp Claude Desktop / Cursor / VS Code - add to config
{
"mcpServers": {
"eltociear-skill-audit-mcp": {
"url": "https://eltociear-skill-audit.hf.space/mcp"
}
}
} Same JSON for Cursor. For VS Code, rename the top-level key from `mcpServers` to `servers`.
Using another client? Same JSON, different key
Claude Desktop · mcpServers
Cursor · mcpServers
VS Code · servers
Windsurf · mcpServers
Zed · context_servers
Cline · mcpServers
Roo Code · mcpServers
Continue · mcpServers
LibreChat · mcpServers
Gemini CLI · mcpServers
Codex CLI · mcp_servers
Full setup guides: every client.
02 · Evidence
https://eltociear-skill-audit.hf.space/mcp
transport: streamable-http
endpoint alive - responded to MCP initialize · probed 2026-08-25
Security posture
What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.
runs as remote - your agent's requests go to eltociear-skill-audit.hf.space
endpoint auth accepted our unauthenticated MCP initialize - no credentials needed to connect
license no standard license detected - usage rights unclear; check the repo before commercial use
registry namespace io.github.eltociear is GitHub-verified and matches the repo owner
03 · What Skill Audit MCP can do
Prose above is summarized from the project's README and registry record - no invented capabilities.
Latest releases
v1.0.1 · 2026-05-11
Adds Cline marketplace approval requirements and broadens distribution: · llms-install.md: explicit LLM-driven install instructions · SECURITY.md: vulnerability reporting policy · alpine-based scanner image…
v1.0.0 · 2026-04-30
Scan MCP servers, AI agent skills, and plugins for 68+ malicious patterns. · Credential exfiltration · Prompt injection · Code execution · Seed phrase harvesting · Download & execute · Identity impersonation · Add to…
04 · Who maintains Skill Audit MCP
skill-audit-mcp is maintained by eltociear. We track 4 MCP servers from eltociear - 4 actively maintained, 8 combined GitHub stars, oldest repo from Apr 2026.
05 · Facts
- repository
- github.com/eltociear/skill-audit-mcp
- category
- security - ranked #143 of 182 actively-maintained security servers as of 2026-08-25.
- registry
- io.github.eltociear/skill-audit-mcp (active, first published 2026-06-07 · 2 versions)
06 · Skill Audit MCP FAQ
What is Skill Audit MCP?
Cross-referenced from the discovery channels that AI/security engineers actually read. It is available as a remote MCP endpoint.
Is Skill Audit MCP still maintained?
Yes - as of 2026-08-25, its last commit was 2026-08-19. We re-verify nightly.
How do I install Skill Audit MCP?
Run `claude mcp add eltociear-skill-audit-mcp --transport http https://eltociear-skill-audit.hf.space/mcp`. You can also paste the ready-made client config above.
Does Skill Audit MCP require authentication?
No - the endpoint accepted our unauthenticated MCP initialize when probed on 2026-08-25; you can connect without credentials.
07 · Alternatives to Skill Audit MCP
Alternatives to Skill Audit MCP
Maintained security servers if Skill Audit MCP isn't the fit.
- SafeDep Vet MCP Protect your AI agents and IDEs from malicious open-source packages. ★ 1,102 · 2026-08-24
- SonarQube MCP Server Analyze code quality and security with SonarQube Server or Cloud directly in AI assistants. ★ 632 · 2026-08-24
- Decionis MCP Server Fail-closed policy gate for AI agent actions, with local evaluation and native pre-tool hooks. ★ 533 · 2026-08-24
- HOL Guard Local-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server. ★ 470 · 2026-08-25
- Emisar Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step. ★ 409 · 2026-08-23
- Bradesco MCP server for Bradesco - Pix, Cobrança (boleto), Arrecadação, Extrato (OAuth2 + mTLS) ★ 269 · 2026-08-12
Pairs well with
Servers that cover what Skill Audit MCP doesn't - only shown when the pairing reason fits the companion.
More security MCP servers · Sanction · Haldir · Flagrix · Clover Public · Zendesk MCP Server
More Python MCP servers · Memory Fabric · Emercoin Agent · Semahash · Blender Optics Simulator · Evc Team Relay MCP · see all