Research: mcp-security-audit
Cached research evidence for mcp-security-audit (not authority).
Purpose
Section titled “Purpose”Skill (sourced via awesome-copilot / mcp ecosystem) for performing security audits on Model Context Protocol (MCP) servers and tools: tool surface review, auth, input validation, sandboxing, data exposure risks in agent tool use.
Harness Coverage
Section titled “Harness Coverage”Target agents: antigravity, claude-code, codex, crush, cursor, gemini-cli, github-copilot, grok, opencode.
Trust And Risks
Section titled “Trust And Risks”trust_tier=needs-inspection; status=inspect-then-install; provenance=verified-install-command; GitHub curated or MCP community; meta-security for the new MCP surface which agents use to act on local/remote resources - high value but emerging standard; inspect for coverage depth and false-negative risk.
Install Prerequisites
Section titled “Install Prerequisites”Install: via github/awesome-copilot or mcp related; status=inspect-then-install; selector=named; policy=Inspect source, hooks, scripts, credentials, and dedupe before install.
Upstream Maintainer
Section titled “Upstream Maintainer”MCP community / github/awesome-copilot (curated)
Comparable Alternatives
Section titled “Comparable Alternatives”agent-governance, agent-owasp-compliance, agent-supply-chain, secret-scanning; general tool-use security audits.
> Evidence synthesized from public web sources (GitHub repos, official docs, skill registries); confidence reflects source reputation and public signals only. Not an endorsement.
