SkillAgentSearch skills...

mcp-audit

Audit the configured MCP servers (user + project scope) via the Agent Monitor Config Explorer API: transport (stdio vs http), command/args and env variable names, headers, and the source file each definition came from. Reads /api/cc-config/mcp

Install / Use

npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill mcp-audit

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

85/100

Category

Operations

Supported Platforms

Universal

Our assessment of mcp-audit

mcp-audit scores 85/100 on our quality scale, 486th of 736 Operations skills we index.

Its SKILL.md is 2.7 KB long, well organised into 8 sections and no code examples: a solid amount of guidance for an agent.

With 1,015 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
26/30
Structure
13/20
Description
15/15
Adoption
13/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 12 days ago, so mcp-audit is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

mcp-audit compared with similar skills

All 4 of these similar skills score higher than mcp-audit; compare them before choosing.

SkillScoreStarsUpdatedFormat
mcp-audit (this skill)by hoangsonww851.0k12d agoSKILL.md
Agent-Reachby Panniantong10092.4k21d agoCLAUDE.md
headroomby headroomlabs-ai10074.5ktodayCLAUDE.md
CowAgentby zhayujie10047.2ktodayCLAUDE.md
Scraplingby D4Vinci10085.9ktodayMCP Server

Frequently asked questions

How do I install mcp-audit?
Run npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill mcp-audit. The install tabs above show the steps for each supported agent.
Which AI agents does mcp-audit work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is mcp-audit safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is mcp-audit still maintained?
The repository was last updated 12 days ago, so mcp-audit is actively maintained.

name: mcp-audit description: > Audit the configured MCP servers (user + project scope) via the Agent Monitor Config Explorer API: transport (stdio vs http), command/args and env variable names, headers, and the source file each definition came from. Reads /api/cc-config/mcp. Use when reviewing MCP integrations for hygiene, duplication, or unexpected transports.

MCP Audit

Inventory and audit every Model Context Protocol server the user has configured — both user-scope and project-scope — read through the Agent Monitor dashboard at http://localhost:4820.

Input

The user provides: $ARGUMENTS

This may be:

  • empty — audit all MCP servers (default).
  • a server name fragment — focus on matching servers.
  • "stdio" / "http" — restrict to one transport kind.

Data Sources

| Endpoint | Returns | |----------|---------| | GET /api/cc-config/mcp | { user:[…], projectScoped:[…] }. Each server: { name, source, kind } where kind is stdio (with command, args, envNames), http (with url, headers), or unknown. source names the file the definition came from (e.g. ~/.claude.json (top-level), ~/.claude.json (projects[<root>]), ~/.claude/settings.json) |

Report Sections

1. Server inventory

List every server from user and projectScoped. For each show name, source, kind, and the transport detail:

  • stdio — the command, its args, and the envNames (names only — values are not exposed by the API).
  • http — the url and the headers key names (values not exposed).
  • unknown — a definition the server could not classify; flag it for review.

2. Scope split & duplication

Separate user-scope from project-scope servers. Flag any name that appears in both scopes (project may shadow user) and any duplicate definitions across source files.

3. Hygiene flags

  • Unknown transport — servers with kind: "unknown" (malformed or unsupported definition).
  • Env reliance — stdio servers with many envNames; note they depend on environment variables being present at launch.
  • Remote endpoints — http servers; surface the url host so the user can confirm they trust the remote.

Output

  • Section 1 as a table (Scope | Name | Kind | Transport detail | Source).
  • Env names and header names listed by name only — never invent or print values (the API does not expose them).
  • Cite only fields the API returned — never fabricate servers, commands, or hosts.
  • Note: MCP servers are read-only via the Config Explorer (they are written concurrently by the running CLI); edit their definitions in the source file named by source.
  • If the dashboard is unreachable at http://localhost:4820, say so and tell the user to start it with npm start from the repo root.

Related Skills

View on GitHub
GitHub Stars1.0k
CategoryOperations
Updated12d ago
Forks238

Languages

JavaScript

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions