Developer · Remote MCP server
Skill Audit MCP
MCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.eltociear/skill-audit-mcp- Version
- 1.2.0
- Status
- Active
- Category
- developer
- Transport
- Streamable HTTP, stdio (local process)
- Package
- OCI image (Docker)
- Published
- 2026-09-30
- Updated
- 2026-09-30
- Publisher
- eltociear (GitHub) · 6 servers with pages here
- Repository
- github.com/eltociear/skill-audit-mcp
- Source
- Registry API entry
Remote endpoints
| Transport | URL | Headers declared |
|---|---|---|
| Streamable HTTP | https://eltociear-skill-audit.hf.space/mcp | None |
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| OCI image (Docker) | ghcr.io/eltociear/skill-audit-mcp:mcp-1.2.0 | — | stdio |
How to connect Skill Audit MCP
Skill Audit MCP is a remote MCP server: there is nothing to install. Its endpoint is https://eltociear-skill-audit.hf.space/mcp, served over Streamable HTTP. In an assistant that accepts remote MCP servers (often under a setting named connectors, integrations or tools), add a new server and give it this URL; in a client configured by file, add it as a remote (HTTP) server with the same URL.
No headers are declared in the registry entry. If the server needs you to sign in, a client that supports MCP authorization opens the service's own sign-in page when it first connects.
It can also run locally from a container image in an OCI registry such as Docker Hub or GitHub Container Registry: ghcr.io/eltociear/skill-audit-mcp:mcp-1.2.0. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Docker or another OCI container runtime; started with docker run — the usual command is docker run -i --rm ghcr.io/eltociear/skill-audit-mcp:mcp-1.2.0.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"skill-audit-mcp": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"ghcr.io/eltociear/skill-audit-mcp:mcp-1.2.0"
]
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from eltociear (GitHub)
| Server | Runs |
|---|---|
| Contract Guard MCPEVM contract/token risk check + ERC20 approval (proxy, EIP-7702, unlimited-allowance). Zero deps. | Local · stdio |
| Repo Security Scanner — Malicious Code & Supply ChainAudit GitHub repos for malicious and supply-chain code before you depend on them. | Remote · HTTP |
| Secrets Audit MCPDetects leaked secrets & API keys: 32+ provider rules (AWS, GitHub, Stripe, OpenAI…), zero deps. | Local · stdio |
| Tokenguard MCPReal-world data for agents: air quality, geocoding, quakes, holidays, web search. | Remote · HTTP |
| URL to Clean Markdown for LLMs & RAGFetch URLs and return clean Markdown for RAG — nav, ads and boilerplate stripped. | Remote · HTTP |
More developer servers
| Server | Runs |
|---|---|
| SkeletIQHand a released SkeletIQ architecture to a coding agent: brief, build order, drift check. | Local · stdio |
| SkeletongraphZero-LLM structural code retrieval for AI coding agents, served over MCP. | Local · stdio |
| SketchdexAn MCP server that lets AI agents draw hand-drawn Excalidraw diagrams as files on your machine. | Local · stdio |
| SkifflyDeploy apps and databases on Skiffly: projects, services, deployments, logs, variables, domains. | Remote · HTTP |
| Skill Builder MCPSearch the skill-builder registry and auto-install skills for Claude Code, Cursor, and Codex. | Local · stdio |
| Skill of SkillsQuality-ranked, cross-platform directory of AI coding skills, plugins and MCP servers. | Remote · HTTP |
| SKILL.md LintLint a SKILL.md for frontmatter, structure, secrets and size. All 6 tools free. | Remote · HTTP |
| SkillAgentSearch and fetch AI agent skills, rules files and MCP servers indexed from GitHub. | Remote · HTTP |