All Agent Skills

Security, Quality & Compliance

auditing-mcp-servers-for-tool-poisoning

Auditing MCP Servers For Tool Poisoning is a source-indexed Agent Skill for security, quality & compliance work. Based on the SKILL.md description, it focuses on audit mcp servers for tool poisoning, tool shadowing, rug pulls, ssrf, and unauthenticated exposure…. Use the linked GitHub file to confirm scope and prerequisites before enabling it.

Read original SKILL.md
Review it in your own environment.

AI Vitamin indexes this source file; it does not certify safety, quality, compatibility, permissions, or outcomes.

What this Skill does

Auditing MCP Servers For Tool Poisoning is a source-indexed Agent Skill for security, quality & compliance work. Based on the SKILL.md description, it focuses on audit mcp servers for tool poisoning, tool shadowing, rug pulls, ssrf, and unauthenticated exposure…. Use the linked GitHub file to confirm scope and prerequisites before enabling it.

What the author says

Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and description pinning. Use before adding a new MCP server to an agent stack, when reviewing an internal MCP server, detecting rug pulls, or investigating an agent's unexpected tool-driven behavior.

Compatibility and requirements

  • Use an agent runtime that supports Agent Skills and the linked SKILL.md format.
  • Confirm the source repository's tools, SDKs, and platform prerequisites for security and compliance work.

How to install or import it

  • Open the linked GitHub SKILL.md and review its scope and setup instructions.
  • Install or import the skill using the agent runtime's documented workflow.
  • Run a small, non-sensitive test and verify the output before broader use.

Permissions and risks

  • Review every command, file path, network request, dependency, and credential scope before enabling it.
  • GitHub stars indicate popularity, not safety or correctness; validate the source and test with non-sensitive data.

Example workflows

  • Ask an AI agent to apply Auditing MCP Servers For Tool Poisoning to security and compliance work described in the source record.
  • Have the agent state assumptions, required tools, and expected output before using this security, quality & compliance skill.
  • Compare the result with the linked GitHub SKILL.md and verify it against your project requirements.

Related Agent Skills

More source records in Security, Quality & Compliance.

View category