Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Runs a defensive, read-only security audit of the local machine for MCP and AIagent risks: risky bindings, MCP config issues, and confused-deputy exposu re.Use before enabling MCP servers or when the user says audit mcp, check lo calhost exposure, mcp security. Outputs text, JSON, SARIF, or HTML. Triggers : audit mcp, mcp security, defensive-mcp-audit. Use when the user needs this capability.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-02 | ✗→✓ | ▲ Improved | -16% | 0% |
| case-03 | ✗→✓ | ▲ Improved | -21% | 0% |
| case-07 | ✗→✓ | ▲ Improved | -53% | 0% |
| case-08 | ✗→✓ | ▲ Improved | -19% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 169% | 0% |
exposed-service-triagemcp-tool-scouthitl-approver| Failure | Response | |---------|----------| | Tool not installed | pip install defensive-mcp-auditcli] or clone github.com/Stijnman/defensive-mcp-audit. | | Permission denied on ss | Report limitation; suggest user-run with adequate permissions. |
This skill is designed for public distribution. Constraints:
Input: User request matching triggers above. Output: Structured result per workflow; local artifacts only unless user opts in.
Other measured skills in the registry, with their headline benchmark lift.