Scan agent skills and MCP servers for malicious patterns before you load them
AI & Agentsv1.1.0streamable-httpeltociear-skill-audit.hf.space repository
| Criterion | Points | Observed |
|---|---|---|
| reachability | 25 / 25 | HTTP 200, initialize accepted in 746ms |
| protocol | 15 / 15 | valid JSON-RPC initialize result, protocolVersion 2025-06-18, serverInfo skill-audit@1.1.0 |
| tooling | 35 / 35 | tools/list OK: 10 tools e.g. "air_quality"; 10/10 described, 10/10 fully-typed schemas, median description 144 chars |
| latency | 7 / 10 | initialize round-trip 746ms |
| provenance | 15 / 15 | description present; repository linked; version 1.1.0; namespace io.github.eltociear matches endpoint/repo |
Score 97/100 · latency 746ms · 10 tools · protocol access: open ⓘ
Security, data integrity, citation quality, and advertised claims are measured separately from protocol uptime. Missing evidence is marked unverified, never converted into a pass.
| Dimension | Metric | Status | Evidence | Source |
|---|---|---|---|---|
| security | sensitive_capabilities_declared | concern | 2 discovered tool(s) advertise potentially state-changing or privileged capabilities. Tool names: audit_skill_text, audit_skill_url. Classification is description-based and does not prove exploitability. Observed value: audit_skill_text, audit_skill_url Sample: n=2 | live_probe |
| security | authentication_boundary | observed | Live protocol probe observed auth_state=open. This describes discovery/access behavior; it is not by itself a vulnerability finding. Observed value: open | live_probe |
Machine-readable receipt: /api/trust/io.github.eltociear/skill-audit-mcp.json
Claude Code:
claude mcp add --transport http skill-audit-mcp https://eltociear-skill-audit.hf.space/mcp
Generic MCP client config:
{ "mcpServers": { "skill-audit-mcp": { "type": "http", "url": "https://eltociear-skill-audit.hf.space/mcp" } } }
MCP Queen is a graded index, not a middleman — your agent connects directly to the server above. Check the grade and evidence first; that's the point.
Share this server: permalink https://mcpqueen.com/s/io.github.eltociear/skill-audit-mcp · referral link https://mcpqueen.com/go/io.github.eltociear/skill-audit-mcp (counts as “routed via the queen”).
Live operational-grade badge, re-probed continuously — not a security or data-quality certification. Put it in your README and link to the complete receipt:
[](https://mcpqueen.com/s/io.github.eltociear/skill-audit-mcp)
Think the grade is wrong? Fix the finding the evidence shows, then the next probe cycle picks it up automatically (full cycle ≈ 3 days) — or open a dispute via the MCP endpoint.
Email alerts when the grade changes or the endpoint stops answering. Double-opt-in, one-click unwatch, free while in beta.
| When (UTC) | Grade | Score | Latency |
|---|---|---|---|
| 2026-07-29 16:45 | A | 97 | 746ms |