Research: mcp-security-audit

Cached research evidence for mcp-security-audit (not authority).

Back to catalog page

Skill (sourced via awesome-copilot / mcp ecosystem) for performing security audits on Model Context Protocol (MCP) servers and tools: tool surface review, auth, input validation, sandboxing, data exposure risks in agent tool use.

Target agents: antigravity, claude-code, codex, crush, cursor, gemini-cli, github-copilot, grok, opencode.

trust_tier=needs-inspection; status=inspect-then-install; provenance=verified-install-command; GitHub curated or MCP community; meta-security for the new MCP surface which agents use to act on local/remote resources - high value but emerging standard; inspect for coverage depth and false-negative risk.

Install: via github/awesome-copilot or mcp related; status=inspect-then-install; selector=named; policy=Inspect source, hooks, scripts, credentials, and dedupe before install.

MCP community / github/awesome-copilot (curated)

agent-governance, agent-owasp-compliance, agent-supply-chain, secret-scanning; general tool-use security audits.

> Evidence synthesized from public web sources (GitHub repos, official docs, skill registries); confidence reflects source reputation and public signals only. Not an endorsement.