This skill as a file
$7 one payment, yours forever
- Download right after checkout, keep it for good
- Paste it into ChatGPT, Claude, Gemini or any AI chat, free plans included
- 30-day money-back guarantee
MCP Security Reviewer checks an MCP server or client config before you connect it to Claude.
Pacchetto skill completo download immediatomcp-security-reviewer.md
Questo e altri 2,500+, dentro la tua IA
AI CRM includedPaghi una volta, tuo per sempreDownload immediatoSoddisfatti o rimborsati 30 giorni
As featured onProduct HuntFazierKittyLaunch
Secure checkout by Shopify
Trademarks of their respective owners. KissMySkills is not affiliated with or endorsed by them.
Oppure tutti gli skill, dentro la tua IA.
Domande prima di comprare? Risponde una persona, di solito in giornata: hello@kissmyskills.com
// the file itself
The first lines of the file your AI will read, exactly as delivered. Nothing rewritten for the page.
You are an application security reviewer for MCP servers and client configs who never runs untrusted code. You have been activated to find prompt injection, over-broad scopes and token leaks and to write the fixes.
// two ways to get it
$7 one payment, yours forever
$9/mo cancel anytime, or $59 a year
Subscribers can still buy single files and keep them after they cancel.
MCP Security Reviewer checks an MCP server or client config before you connect it to Claude. Give it the server code, the tool definitions and your claude_desktop_config.json or connector settings, and it returns findings by severity with the file and line, the evidence, a short exploit scenario and the fixed code.
Built for developers shipping MCP servers and teams deciding which third-party servers to allow. It looks for prompt injection through tool results and descriptions, tool poisoning and silent description changes, over-broad scopes, token passthrough, tokens in logs or URLs, missing audience checks, SSRF, command injection and path traversal, unauthenticated remote endpoints, local servers exposed on 0.0.0.0, secrets in config files and unpinned packages. It is a static review and never runs an untrusted server; it reviews security rather than designing tools.
Finds the holes an attacker would use before an MCP server gets access to your files, inbox or production API.
Compatible with: MCP TypeScript and Python servers, Cloudflare Workers remote MCP, Claude Desktop and Claude Code configs, Claude.ai connectors and other MCP clients.
Dopo il pagamento, il link per il download arriverà nella tua casella di posta. Salva il file in qualsiasi posizione sul tuo dispositivo.
Claude, ChatGPT, Gemini, Grok o Copilot: qualunque sia quello che usi già.
Inseriscilo nel prompt di sistema, nelle istruzioni del progetto o nel campo delle istruzioni personalizzate.
La tua AI è ora configurata come specialista. Chiedile qualsiasi cosa nell’ambito di sua competenza.
Non è richiesta alcuna conoscenza tecnica.
Con Unlimited non c’è niente da scaricare. Collega la tua IA una volta, poi chiedi qualsiasi skill per nome.
Guida alla configurazione → Unlimited · $4.92/mese con il piano annuale →
It statically reviews MCP server code and client configs and returns findings by severity: prompt injection and tool poisoning, over-broad scopes, token passthrough and leaks, SSRF, command injection, path traversal, missing auth and secrets in config, each with location, evidence, an exploit scenario and a code fix.
Untrusted text in tool results or descriptions that steers the model, tools with more access than the task needs, tokens passed through or logged, remote endpoints without proper OAuth, local HTTP servers open to the network, and install commands that pull unpinned packages.
Yes. It checks that tokens are issued for your server and validated for audience, that scopes match each tool, that upstream tokens are never passed through, and that tokens never appear in logs, URLs or config files.
No. Builders write and deploy servers and tool-design skills tune schemas. This skill attacks the design on paper and tells you what to fix before anyone connects it.