SkillAgentSearch skills...

mcp-custos

Secure-coding guardian for AI agents — official CWE/NIST/ASVS guidance in-context, enforced at commit, proven at audit.

Install / Use

claude mcp add an0malous -- npx -y github:an0malous/mcp-custos

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

73/100

Category

Security

Supported Platforms

Claude Code
Claude Desktop

Our assessment of mcp-custos

mcp-custos scores 73/100 on our quality scale, 711th of 790 Security skills we index.

Its MCP Server is 3.9 KB long, split into 7 sections with 7 code examples: a solid amount of guidance for an agent.

It has 3 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
26/30
Structure
18/20
Description
12/15
Adoption
3/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated about 2 months ago, so mcp-custos is actively maintained.
  • Our last check on 2026-09-18 found the source still online.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.

Automated pattern scan on 2026-09-29. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

mcp-custos compared with similar skills

All 4 of these similar skills score higher than mcp-custos; compare them before choosing.

SkillScoreStarsUpdatedFormat
mcp-custos (this skill)by an0malous73356d agoMCP Server
Agent-Reachby Panniantong10086.0k13d agoCLAUDE.md
headroomby headroomlabs-ai10074.0ktodayCLAUDE.md
rufloby ruvnet10073.4ktodayCLAUDE.md
CowAgentby zhayujie10047.2ktodayCLAUDE.md

Frequently asked questions

How do I install mcp-custos?
Run claude mcp add an0malous -- npx -y github:an0malous/mcp-custos. The install tabs above show the steps for each supported agent.
Which AI agents does mcp-custos work with?
It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
Is mcp-custos safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is mcp-custos still maintained?
The repository was last updated about 2 months ago, so mcp-custos is actively maintained.

Custos

Custos is a secure-coding helper for AI agents — an MCP server that puts official security guidance in the agent's context while it writes code, enforces that the guidance lands, and turns the result into audit evidence.

Guide → Enforce → Prove

Guide — official secure-coding guidance, in-context, at write time. MCP tools over the full MITRE CWE corpus (944 weaknesses with official mitigations and vulnerable/fixed code examples), NIST 800-53 Rev 5, OWASP ASVS 5.0, NIST SSDF, ISO 27001/27017, and NIST cloud guidance. controls_for_change turns "add password reset" into the exact controls and mitigations before a line is written; cwe_lookup turns any scanner finding into remediation guidance. All text verbatim from the official publications — nothing AI-generated, no network at runtime.

Enforce — the guidance has to land in code. A pre-edit nudge (Claude Code hook) surfaces relevant controls and CWE mitigations — split into design-phase and implementation-phase hints, so the reader picks what fits where they are — the moment a security-touching edit starts, and a pre-commit/CI gate blocks commits to security-sensitive code that carry no citation receipt (// Refs: NIST IA-5(1) inline or in the commit message). Advisory at edit time, enforced at commit, non-bypassable in CI (--strict).

Prove — audit evidence out the other end. custos-evidence walks a repo, collects every citation, resolves NIST → ISO 27001 Annex A through the official NIST OLIR mappings, and emits a COMPLIANCE.md evidence index with file:line pointers.

Install

Requires Bun.

bun add -g mcp-custos        # or: npm install -g mcp-custos

Claude Code

claude mcp add custos -- mcp-custos

Any other MCP client (Claude Desktop, Cursor, …) — add to its MCP config:

{ "mcpServers": { "custos": { "command": "mcp-custos" } } }

The pre-edit nudge is Claude Code-specific; the tools, commit gate, CI check, and evidence generator work with any agent (or none).

Project setup (optional hooks + server registration)

Two install styles, one command either way:

Team (recommended) — add it as a devDependency so teammates get it with plain pnpm install and the lockfile keeps everyone on the same version:

pnpm add -D mcp-custos                 # or npm i -D / yarn add -D / bun add -d
pnpm exec custos-init .

Solo/global — with the package installed globally:

custos-init /path/to/your/project      # --skip-hooks=husky,ci to skip layers

custos-init detects the install mode (override with --local/--global), registers the custos server in the project's .mcp.json (matched to your package manager), and copies three opt-in layers: .claude/settings.json (pre-edit nudge), .husky/pre-commit (citation gate — requires husky in the project), and a GitHub Actions workflow (the same gate with --strict). Existing files are never overwritten. Humans can git commit --no-verify locally; CI is the backstop.

Generate audit evidence

custos-evidence /path/to/your/repo --out=COMPLIANCE.md

Data and provenance

All datasets are bundled (src/data/) and refreshed from official sources via bun run update-sources: the MITRE cwec catalog, NIST OSCAL (800-53, SSDF), the OWASP ASVS release JSON, NIST OLIR mappings, and verbatim extracts from the NIST cloud SPs. ISO standard text is not shipped (paywalled) — only IDs/titles, with implementation detail coming from the mapped NIST controls. The only project-curated (non-official) data: the CWE→ASVS/NIST starter mappings and the Top 25 overlay, labeled as such inside the dataset.

Development

git clone https://github.com/an0malous/mcp-custos && cd mcp-custos
bun install
bun link            # exposes the mcp-custos / custos-* commands from this checkout
bun run typecheck && bun test

Feature work runs through the Kiro spec flow — see CLAUDE.md.

MIT © an0malous

Related Skills

View on GitHub
GitHub Stars3
CategorySecurity
Updated1mo ago
Forks0

Languages

TypeScript

Trust signals

92/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 low