MCP Security Reviewer

MCP Security Reviewer

$7.00
Accéder aux informations sur le produit
MCP Security Reviewer

MCP Security Reviewer

MCP Security Reviewer checks an MCP server or client config before you connect it to Claude.

$7.00 ce skill un seul paiement à vous pour toujours

Pack skill complet téléchargement immédiatmcp-security-reviewer.md

Unlimited
Or get every skill, not just this one $9/mois

Celui-ci et 2,500+ autres, dans votre IA

Ce skill$7
Unlimited$9/mois

Payez une fois, gardez-le pour toujoursTéléchargement immédiatSatisfait ou remboursé 30 jours

As featured onProduct HuntFazierKittyLaunch

  • American Express
  • Apple Pay
  • Bancontact
  • BLIK
  • Google Pay
  • Klarna
  • Maestro
  • Mastercard
  • MB WAY
  • MobilePay
  • PayPal
  • Union Pay
  • Visa

Secure checkout by Shopify

Trademarks of their respective owners. KissMySkills is not affiliated with or endorsed by them.

Ou tous les skills, directement dans votre IA.

0:33 · sans son
Les 2,500+ avec Unlimited · $9/mois en annuel →

Des questions avant d’acheter ? Une personne répond, souvent le jour même : hello@kissmyskills.com

// the file itself

Read it before you buy it.

The first lines of the file your AI will read, exactly as delivered. Nothing rewritten for the page.

Utilisez le prenom
Une fois le fichier charge, parlez-lui par son prenom : « Serge, regarde cette page. » C'est a cela que sert le prenom. Cela garde aussi plusieurs skills distincts dans un meme chat.
// le skill qui fait tourner votre IA

You are an application security reviewer for MCP servers and client configs who never runs untrusted code. You have been activated to find prompt injection, over-broad scopes and token leaks and to write the fixes.

223 lignes · .md · telechargement immediat

// two ways to get it

Buy this file, or open the whole library.

Buy once

This skill as a file

$7 one payment, yours forever

  • Download right after checkout, keep it for good
  • Paste it into ChatGPT, Claude, Gemini or any AI chat, free plans included
  • 30-day money-back guarantee
Unlimited Access

Every skill, prompt and agent, inside your chat

$9/mo cancel anytime, or $59 a year

  • All 2,500+ files in the library, loaded the moment you ask
  • Nothing to download or paste: connect once in Claude, ChatGPT, Claude Code or Cursor
  • Works on every Claude plan, free included · 30-day money-back guarantee on the first charge
See Unlimited Access →

Subscribers can still buy single files and keep them after they cancel.

What you're actually buying

MCP Security Reviewer checks an MCP server or client config before you connect it to Claude. Give it the server code, the tool definitions and your claude_desktop_config.json or connector settings, and it returns findings by severity with the file and line, the evidence, a short exploit scenario and the fixed code.

Built for developers shipping MCP servers and teams deciding which third-party servers to allow. It looks for prompt injection through tool results and descriptions, tool poisoning and silent description changes, over-broad scopes, token passthrough, tokens in logs or URLs, missing audience checks, SSRF, command injection and path traversal, unauthenticated remote endpoints, local servers exposed on 0.0.0.0, secrets in config files and unpinned packages. It is a static review and never runs an untrusted server; it reviews security rather than designing tools.

Finds the holes an attacker would use before an MCP server gets access to your files, inbox or production API.

Compatible with: MCP TypeScript and Python servers, Cloudflare Workers remote MCP, Claude Desktop and Claude Code configs, Claude.ai connectors and other MCP clients.

  • What is MCP tool poisoning? Hidden instructions in a tool description or result that steer the model; the reviewer flags them with the exact text.
  • Does it check OAuth? Yes - token audience, scopes, passthrough, storage and redirect handling.
  • Can it review a server I did not write? Yes - paste the code or config; it never executes it.
  • What do I get at the end? A findings table, a scope matrix per tool, a config review and a fix order.
// installation Moins de 2 minutes

Quatre étapes. N’importe quel chat AI.

  1. 01
    Télécharger le fichier

    Après le paiement, le lien de téléchargement arrive dans votre boîte de réception. Enregistrez le fichier où vous voulez sur votre appareil.

  2. 02
    Ouvrez votre conversation AI

    Claude, ChatGPT, Gemini, Grok ou Copilot — celui que vous utilisez déjà.

  3. 03
    Collez le contenu du fichier

    Insérez-le dans le prompt système, les instructions du projet ou le champ des instructions personnalisées.

  4. 04
    Commencez à travailler

    Votre AI est maintenant configurée comme spécialiste. Posez-lui n’importe quelle question relevant de son domaine.

Aucune connaissance technique requise.

Avec Unlimited, rien à télécharger. Connectez votre IA une fois, puis demandez n’importe quel skill par son nom.

Guide d’installation → Unlimited · $4.92/mois en annuel →

// faq

Questions concernant ce produit

What does MCP Security Reviewer do?+

It statically reviews MCP server code and client configs and returns findings by severity: prompt injection and tool poisoning, over-broad scopes, token passthrough and leaks, SSRF, command injection, path traversal, missing auth and secrets in config, each with location, evidence, an exploit scenario and a code fix.

What are the main MCP security risks?+

Untrusted text in tool results or descriptions that steers the model, tools with more access than the task needs, tokens passed through or logged, remote endpoints without proper OAuth, local HTTP servers open to the network, and install commands that pull unpinned packages.

Does it check MCP OAuth and token handling?+

Yes. It checks that tokens are issued for your server and validated for audience, that scopes match each tool, that upstream tokens are never passed through, and that tokens never appear in logs, URLs or config files.

Is it the same as an MCP builder or tool-design skill?+

No. Builders write and deploy servers and tool-design skills tune schemas. This skill attacks the design on paper and tells you what to fix before anyone connects it.

Prêt à spécialiser votre AI ?

ou celui-ci et 2,500+ autres avec Unlimited · $4.92/mois en annuel →