mcp-security-reviewer
Use before connecting a new MCP server to your agent — produces a structured security review covering source, permissions, tools, network, and approvals.
pinned to #7f8ee3cupdated 2 weeks ago
Ask your AI client: “install skills/mcp-security-reviewer”.
Requires the metahub MCP server installed in your client. Set up MCP.
mh install skills/mcp-security-reviewermetahub onboarded this repo on the author's behalf.
If you own github.com/oxbshw/LLM-Agents-Ecosystem-Handbook on GitHub, claim the listing to take over publishing. Your claim preserves the existing eval history and badges; only the curator label is replaced with verified-publisher on your next publish.
Stars
533
Last commit
2 weeks ago
Latest release
published
- #ai
- #ai-agent
- #ai-agents
- #fine-tuning
- #finetuning-llms
- #freamework
- #llm
- #llmops
- #local-development
- #mcp-server
- #memory
- #rag
- #rag-chatbot
- #voice-agent
Evaluation report
WarningsAutomated checks the publisher passed at publish time — structure, docs, safety, and whether the artifact behaves as claimed.7f8ee3c· 2 weeks ago
Documentation
41Description quality
23 words · 153 chars — "Use before connecting a new MCP server to your agent — produces a structured sec…"
README is present and substantial
19,199 chars · 20 sections · 2 code blocks
Tags / topics declared
14 total — ai, ai-agent, ai-agents, fine-tuning, finetuning-llms, freamework (+8)
README has usage / example sectionswarn
README has no Usage / Example / Quick start / Installation heading at any level
Add a `# Usage`, `## Quick start`, or similar section so end users can copy/paste a working invocation. Code blocks alone work too if there are several.
Homepage / docs URL declared
no homepage declared (registry will use the repo URL) — info-only, not blocking
Release history
1- releasecurrent7f8ee3cwarn2 weeks ago
Contents
When to use
- A new MCP server is being added to an agent
- An MCP server version is being bumped
- An incident triggered a re-review
Inputs
| Name | Type | Required | Notes |
|---|---|---|---|
repo_url | string | yes | the MCP server's source |
version | string | yes | tag or commit SHA being adopted |
intended_use | string | yes | one paragraph: what we'll let it do |
Workflow
- Source review: clone at the pinned version; check for unexpected files / scripts
- Capabilities: list every tool and resource exposed; map to risk levels (
references/mcp-risk-matrix.md) - Network: identify outbound endpoints; document and assess each
- Permissions: minimum required scopes / tokens; document over-permissions
- Output handling: confirm the agent treats tool output as untrusted (sanitization, no execution)
- Approvals: define which tools require human approval
- Produce filled
MCP_SERVER.mdinmcp/<server>.md
References
Success criteria
- All tools labelled by risk
- High/Critical tools gated by approval
- Pinned version (no
latest/ floating refs) - Documented network egress
Failure modes
- Source unavailable / un-pinnable → reject
- Discovered hidden tool not in docs → reject and report upstream
Reviews
No reviews yet. Be the first.
Related
Browser Use
🌐 Make websites accessible for AI agents. Automate tasks online with ease.
Gpt Researcher
An autonomous agent that conducts deep research on any data using any LLM providers
Guizang Ppt Skill
AI-agent Skill for generating polished HTML slide decks: editorial magazine and Swiss layouts, image prompts, social covers, and a WebGL/low-power presentation runtime.
mh install skills/mcp-security-reviewer