
Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10.
Listed on
- Official MCP Registry
- Glamavia MCP Toplist
- PulseMCPvia MCP Toplist
First seen 2 Oct 2026. One server, whatever directories list it: each directory listing keeps its own page and history.
3
Directories
2 via MCP Toplist
8
Tools
From an anonymous probe
-
ToolBench grade
Not graded by Arcade
0
GitHub stars
From MCP Toplist
Tools
| Tool | Description | Behaviour |
|---|---|---|
| audit_mcp_server_config | Audit an MCP client configuration for security risks — works offline, no external service required. Detects: tool poisoning, hidden/coercive instructions in tool descriptions, hardcoded credentials, unpinned packages (rug-pull risk), insecure transport, and toxic capability combinations (shell + network, file-read + network). | Not declared |
| check_dependencies | Check the health of your agent's external dependencies: uptime, SSL validity, blacklist status, and a trust score 0-100 (DepScan). | Not declared |
| full_stack_audit | Complete security posture in one call: audits the MCP config, checks dependency health, analyzes an untrusted skill, scans the local network gateway, and scans any payload you're about to send out for secrets/PII — then correlates everything into a single prioritized report. Pass only what you have; each section is skipped gracefully if its input or service is missing. | Not declared |
| network_scan | Active security scan of a device or host with an autonomous AI agent that decides which follow-up probes to run (ActiveScanner). Only scan targets you own or have permission to test. | Not declared |
| scan_secrets | Scan a text payload (a prompt, an outbound API body, a file's contents) for secrets and PII BEFORE it leaves for an LLM or external API, and return a redacted copy. Catches the #1 real-world agent incident: secrets/PII leaking into a model's context. WORKS OFFLINE with no API key — the detection runs in-process (pure regex + Luhn check, no network). If a SecretScan backend key IS configured, the scan is routed there instead (which also persists an audit record). | Not declared |
| scan_skill | Analyze an AI agent skill for prompt injection, malware patterns, and OWASP LLM Top 10 issues BEFORE installing it (SecurityScan). | Not declared |
| securityscan_checkout | Start a Stripe checkout to buy a SecurityScan tier (agent-native sales). Returns a payment URL to hand to your user AND a PENDING API key that activates automatically once payment clears — no other setup step. | Not declared |
| securityscan_pricing | SecurityScan catalog: tiers, prices, quotas and the evidence behind the product — the fact sheet an agent needs to evaluate or recommend a purchase to its user. Fully offline, no API key required. Returns: JSON with the tier table (price / target slots / scan types), the pricing model, benchmark evidence, and how to buy. | Not declared |
| Directory | Listing | Tier | First seen |
|---|---|---|---|
| Official MCP Registry | SecurityScan | - | 2 Oct 2026 |
| Glama | Listed there according to MCP Toplist’s dataset; not collected by InvokeRank. | ||
| PulseMCP | Listed there according to MCP Toplist’s dataset; not collected by InvokeRank. | ||