CCM
/MCP
SkillsMCPMarketplacesDigestToolsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Sales & MarketingWeb & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web Crawling
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Skill index
  • MCP index
  • Marketplace index
  • Plugins Reference

Community

  • About
  • Tools
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by mertbuilds.com

Independent project, not affiliated with Anthropic
megamind-0x avatar

SkillAudit

megamind-0x/skillaudit
HTTP
Summary

A security scanner that checks AI agent skills and MCP servers before your agent installs them. It runs 43 detection rules across 401 patterns, catching credential theft, data exfiltration, prompt injection, obfuscated code, and container escapes. You get a free API with gate checks (allow/deny decisions), full scans, policy enforcement, and MCP manifest analysis for schema poisoning. The CLI works as npx skillaudit with zero config, or as an MCP server tool in Claude Desktop. It returns risk scores (clean/low/moderate/high), outputs SARIF for CI/CD, and includes GitHub Action integration. Premium deep scans with threat chain analysis run on x402 micropayments. Reach for this when you need to gate third party skills in autonomous agent workflows or enforce security policy in agent deployment pipelines.

CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
ego lite browserego lite browser
ego lite browser
Fastest browser for AI agents to run web automation tasks, always free.
Download Free life-time →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
AppSignal
AppSignal
Monitor with ease. Code with confidence.
Start Free Trial →
Agent, connect blockchain
Agent, connect blockchain
Connect your Claude agent to live crypto prices and trading routes via 1inch
Get the MCP →
inference shell
inference shell
create and run specialised agents in minutes
build now →
CodeHealth MCP ServerCodeHealth MCP Server
CodeHealth MCP Server
Protect your code quality, stop the AI slop.
Try For Free →
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
ego lite browserego lite browser
ego lite browser
Fastest browser for AI agents to run web automation tasks, always free.
Download Free life-time →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
AppSignal
AppSignal
Monitor with ease. Code with confidence.
Start Free Trial →
Agent, connect blockchain
Agent, connect blockchain
Connect your Claude agent to live crypto prices and trading routes via 1inch
Get the MCP →
inference shell
inference shell
create and run specialised agents in minutes
build now →
CodeHealth MCP ServerCodeHealth MCP Server
CodeHealth MCP Server
Protect your code quality, stop the AI slop.
Try For Free →

🛡️ SkillAudit

CI npm

The security layer for AI agent skills. Scan, gate, and enforce policy before your agent installs anything.

43 detection rules · 401 patterns · MCP + A2A coverage · Zero dependencies

Live npm API Docs

# Gate check — should my agent install this?
npx skillaudit gate https://example.com/SKILL.md

# Full scan
npx skillaudit https://example.com/SKILL.md

# Scan MCP manifest for schema poisoning
npx skillaudit manifest tools.json

Why SkillAudit?

AI agents install tools, skills, and MCP servers from untrusted sources. Those skills can steal credentials, exfiltrate data, inject prompts, or manipulate other agents — and most of this is invisible to the user.

SkillAudit catches it. One API call before install. That's it.


Quick Start

1. Gate Check (one line)

The infrastructure endpoint. Returns allow/deny.

curl "https://skillaudit.vercel.app/gate?url=https://example.com/SKILL.md"
# → {"allow": true, "decision": "allow", "risk": "clean", ...}

2. Full Scan

curl "https://skillaudit.vercel.app/scan/quick?url=https://example.com/SKILL.md"

3. Bulk Gate (check multiple skills at once)

curl -X POST https://skillaudit.vercel.app/gate/bulk \
  -H "Content-Type: application/json" \
  -d '{"urls": ["https://example.com/skill1.md", "https://example.com/skill2.md"]}'
# → {"allow": false, "denied": 1, "blocked": [...]}

4. Policy Enforcement

curl -X POST https://skillaudit.vercel.app/policy/evaluate-inline \
  -H "Content-Type: application/json" \
  -d '{
    "url": "https://example.com/SKILL.md",
    "policy": {"maxRisk": "low", "blockedCategories": ["credential_theft"]}
  }'

What It Detects

43 rule categories, 401 patterns:

CategoryRulesWhat it catches
🔑 Credential TheftCRED_ENV_READ, TOKEN_STEALReading .env, stealing tokens/cookies, accessing SSH keys
📤 Data ExfiltrationDATA_EXFIL, EXFIL_PATTERN, EXFIL_COVERTWebhook.site, DNS exfil, covert channels, image beacons
💉 Prompt InjectionPROMPT_INJECT, TOOL_POISONING"Ignore previous instructions", hidden system prompts
🧬 MCP Schema PoisoningMCP_SCHEMA_POISONHidden instructions in MCP tool descriptions/schemas
🤖 A2A AttacksA2A_AGENT_IMPERSONATION, A2A_TASK_HIJACK, A2A_CROSS_AGENT_INJECT, A2A_DATA_LEAK, A2A_CAPABILITY_ABUSEAgent Card spoofing, task hijacking, cross-agent injection
🐚 Code ExecutionSHELL_EXEC, REVERSE_SHELLShell commands, reverse shells, eval/Function
🔐 Hardcoded Secrets22 detectorsAWS keys, GitHub tokens, JWTs, private keys, API keys
👻 ObfuscationOBFUSCATION, INVISIBLE_TEXTBase64 payloads, zero-width Unicode, encoded URLs
⏰ EvasionTIME_BOMBDate-triggered activation, delayed execution
🔗 Supply ChainSUPPLY_CHAINRemote code loading, curl|bash, dependency confusion
🌐 NetworkNET_SUSPICIOUS, SSRF_PATTERN, DNS_REBINDSSRF, raw IPs, DNS rebinding, metadata endpoints
📦 Container EscapeCONTAINER_ESCAPEDocker socket, nsenter, /proc traversal, LD_PRELOAD
🔄 PersistencePERSISTENCECron injection, systemd, LaunchAgents, pm2, nohup
🕵️ ReconENV_RECONos.hostname, whoami, network interfaces, environment dump
🔧 Agent ManipulationAGENT_MEMORY_MOD, TOOL_SHADOW, CROSS_TOOL_ACCESSMemory modification, tool shadowing, cross-tool data access
💰 Crypto TheftCRYPTO_THEFTWallet files, seed phrases, MetaMask vaults

Smart context suppression: documentation examples and placeholder tokens are automatically suppressed to minimize false positives.


CLI

Zero install, zero config. Requires Node.js 18+.

# Scan a file, URL, or directory
npx skillaudit SKILL.md
npx skillaudit https://github.com/user/repo
npx skillaudit ./my-agent-project/

# Gate check (CI/CD: exit 0 = allow, exit 1 = deny)
npx skillaudit gate https://example.com/SKILL.md
npx skillaudit gate https://example.com/SKILL.md --threshold high

# Scan MCP manifest for schema poisoning
npx skillaudit manifest tools.json

# CI/CD integration
npx skillaudit SKILL.md --fail-on moderate          # Exit 1 if risk >= moderate
npx skillaudit SKILL.md --markdown >> "$GITHUB_STEP_SUMMARY"  # PR summary
npx skillaudit SKILL.md --json | jq .riskLevel      # Machine-readable

# MCP server mode
npx skillaudit --mcp

API Endpoints

Full interactive docs at skillaudit.vercel.app/docs

Gate (Infrastructure)

EndpointDescription
GET /gate?url=Pre-install gate — allow/warn/deny
POST /gate/bulkCheck multiple skills, one composite decision

Scanning

EndpointDescription
GET /scan/quick?url=Quick scan by URL
POST /scan/contentScan raw content
POST /scan/manifestScan MCP tool manifest for schema poisoning
GET /scan/agent-card?url=Scan A2A Agent Card
GET /scan/npm?package=Scan npm package
GET /scan/pypi?package=Scan PyPI package
GET /scan/repo?repo=Scan GitHub repo
POST /scan/depsScan dependency tree
POST /scan/batchBatch scan (up to 20 URLs)
POST /scan/compareDiff two skill versions
POST /scan/deepDeep scan with threat chains

Policy & Intelligence

EndpointDescription
POST /policy/evaluate-inlineEvaluate against custom policy (no auth)
POST /policyCreate stored policy (API key)
GET /reputation/:domainDomain trust score
GET /feedThreat intelligence feed
GET /badge/scan.svg?url=Embeddable SVG badge
GET /certificate/:idSigned audit certificate

Results

EndpointDescription
GET /scan/:idRetrieve scan result
GET /scan/:id/sarifSARIF v2.1.0 output
GET /report/:idShareable HTML report

Rate limit: 30 req/min per IP. Bypass with API key.


MCP Server

Use SkillAudit as a native tool in Claude Desktop, Cursor, or any MCP client:

{
  "mcpServers": {
    "skillaudit": {
      "command": "npx",
      "args": ["skillaudit", "--mcp"]
    }
  }
}

Tools: skillaudit_gate, skillaudit_scan, skillaudit_scan_content, skillaudit_reputation, skillaudit_batch


GitHub Action

name: SkillAudit
on: [pull_request]
jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - run: npx skillaudit . --fail-on high --markdown >> "$GITHUB_STEP_SUMMARY"

CI/CD Integration

# GitHub Actions — gate check before deploy
npx skillaudit gate "$SKILL_URL" --threshold moderate || exit 1

# Generate PR comment
npx skillaudit ./skills/ --markdown > scan-results.md

# Policy enforcement in pipeline
curl -sf -X POST https://skillaudit.vercel.app/policy/evaluate-inline \
  -H "Content-Type: application/json" \
  -d "{\"url\": \"$SKILL_URL\", \"policy\": {\"maxRisk\": \"low\"}}" \
  | jq -e '.pass == true'

Risk Levels

LevelScoreMeaning
🟢 clean0No issues found
🟡 low1–9Minor concerns, review recommended
🟠 moderate10–24Manual review required
🔴 high25–49Do NOT install without audit
⛔ critical50+Almost certainly malicious

Self-Hosted

git clone https://github.com/megamind-0x/skillaudit
cd skillaudit && npm install && npm start
# → http://localhost:3847

Built by Megamind_0x 🧠

Live App · API Docs · Dashboard · npm

Featured
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
ego lite browserego lite browser
ego lite browser
Fastest browser for AI agents to run web automation tasks, always free.
Download Free life-time →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
AppSignal
AppSignal
Monitor with ease. Code with confidence.
Start Free Trial →
Agent, connect blockchain
Agent, connect blockchain
Connect your Claude agent to live crypto prices and trading routes via 1inch
Get the MCP →
inference shell
inference shell
create and run specialised agents in minutes
build now →
CodeHealth MCP ServerCodeHealth MCP Server
CodeHealth MCP Server
Protect your code quality, stop the AI slop.
Try For Free →
Categories
AI & LLM ToolsSecurity & PentestingData & Analytics
TransportHTTP
UpdatedFeb 15, 2026
View on GitHub

Related AI & LLM Tools MCP Servers

View all →
mstang avatar
Casemgr Mcp

mstang/casemgr-mcp

Shared workspace your AI agent writes to. 184 tools, persistent memory, semantic search.
securityscan-api avatar
SecurityScan

net.apisecurityscan/securityscan

Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10.
netclaus avatar
Oroute

netclaus/oroute

Auto-route AI requests to 13 models (Claude, GPT, Gemini, Qwen, DeepSeek). 57% cost savings.
nexus-api-lab avatar
Nexus Mcp

nexus-api-lab/nexus-mcp

Japanese LLM security — prompt injection detection (jpi-guard) + PII masking (PII Guard). Free.
nicofains1 avatar
AgentWatch

nicofains1/agentwatch

Multi-agent observability: cascade failure detection, heartbeats, and forensic replay
nitishgourishetty avatar
Contextual Mcp Server

nitishgourishetty/contextual-mcp-server

RAG-enabled MCP server using Contextual AI. Supports single-agent and multi-agent modes.