Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Triages exposed TCP listeners found by security audits. Identifies processes on risky bindings and recommends safe remediation. Use after mcp audit or w henuser asks what is on port X, fix exposed service. Triggers: exposed port, whatis listening, fix exposed service. Use when the user needs this capabil ity.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-06 | ✗→✓ | ▲ Improved | -15% | 0% |
| case-08 | ✗→✓ | ▲ Improved | -12% | 0% |
| case-13 | ✗→✓ | ▲ Improved | -12% | 0% |
| case-12 | ✗→✓ | ▲ Improved | 2% | 0% |
| case-18 | ✗→✓ | ▲ Improved | -54% | 0% |
defensive-mcp-audithitl-approver| Failure | Response | |---------|----------| | Cannot identify process | Report port and binding; suggest sudo ss -tlnp with user consent. | | User requests aggressive scan | Decline; offer defensive audit only. |
This skill is designed for public distribution. Constraints:
Input: User request matching triggers above. Output: Structured result per workflow; local artifacts only unless user opts in.
Other measured skills in the registry, with their headline benchmark lift.