SkillAgentSearch skills...

mcp-audit

Audit connected MCP servers for token overhead, redundancy, and security

Install / Use

npx skills add rohitg00/pro-workflow --skill mcp-audit

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

85/100

Category

Security

Supported Platforms

Universal

Our assessment of mcp-audit

mcp-audit scores 85/100 on our quality scale, 612th of 917 Security skills we index.

Its SKILL.md is 2.5 KB long, well organised into 11 sections with 2 code examples: a solid amount of guidance for an agent.

With 2,876 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
26/30
Structure
18/20
Description
12/15
Adoption
15/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 6 days ago, so mcp-audit is actively maintained.
  • No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
  • Its trust signals score 88/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

mcp-audit compared with similar skills

All 4 of these similar skills score higher than mcp-audit; compare them before choosing.

SkillScoreStarsUpdatedFormat
mcp-audit (this skill)by rohitg00852.9k6d agoSKILL.md
Agent-Reachby Panniantong10086.4k15d agoCLAUDE.md
headroomby headroomlabs-ai10074.2ktodayCLAUDE.md
rufloby ruvnet10073.6ktodayCLAUDE.md
CowAgentby zhayujie10047.2ktodayCLAUDE.md

Frequently asked questions

How do I install mcp-audit?
Run npx skills add rohitg00/pro-workflow --skill mcp-audit. The install tabs above show the steps for each supported agent.
Which AI agents does mcp-audit work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is mcp-audit safe to use?
It declares no license and scores 88/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is mcp-audit still maintained?
The repository was last updated 6 days ago, so mcp-audit is actively maintained.

name: mcp-audit description: Audit connected MCP servers for token overhead, redundancy, and security. Use when sessions feel slow or before adding new MCPs. user-invocable: true

MCP Audit

Analyze MCP server overhead and recommend cleanup.

Trigger

Use when:

  • Sessions feel slow or expensive
  • Adding a new MCP server
  • Context fills up quickly
  • Reviewing project configuration

Key Insight

Each MCP server adds ALL its tool descriptions to every API request. A server with 20 tools adds ~2K-4K tokens per request, regardless of whether you use those tools.

Audit Steps

Step 1: List Active Servers

Check all MCP configurations:

cat .claude/settings.json 2>/dev/null | grep -A 50 "mcpServers"
cat ~/.claude/settings.json 2>/dev/null | grep -A 50 "mcpServers"

Step 2: Count Tools Per Server

For each server, estimate token overhead:

  • 1-5 tools: ~200-500 tokens (low overhead)
  • 6-15 tools: ~500-1500 tokens (moderate)
  • 16-30 tools: ~1500-3000 tokens (high)
  • 30+ tools: ~3000+ tokens (excessive — consider tool filtering)

Step 3: Check Usage

Questions to ask:

  • Which servers were actually used this session?
  • Which servers haven't been used in 7+ days?
  • Are there servers with overlapping functionality?
  • Are there servers only needed for specific tasks?

Step 4: Recommend Actions

Disable servers that:

  • Haven't been used in 7+ days
  • Overlap with another active server
  • Are project-specific but you're in a different project

Keep servers that:

  • Are used every session (filesystem, git)
  • Provide unique capabilities needed for current work
  • Have low tool count (<5 tools)

Output

MCP AUDIT
  Active servers: [N]
  Total tools: [N]
  Estimated overhead: ~[N]K tokens per request

  Server Analysis:
    [name] — [N] tools, ~[N] tokens
      Status: KEEP / DISABLE / REVIEW
      Reason: [why]

  Recommendations:
    Disable: [list]
    Keep: [list]
    Review: [list]

  Projected savings: ~[N]K tokens per request (~$X.XX per session)

Thresholds

  • Total servers: <10 (ideal), 10-15 (monitor), >15 (reduce)
  • Total tools: <80 (ideal), 80-120 (monitor), >120 (reduce)
  • Per-server: <15 tools (ok), 15-30 (filter), >30 (split or disable)

Rules

  • Never disable servers without user confirmation
  • Estimate token savings for each recommendation
  • Consider task context — a server might be unused today but critical tomorrow
  • Check for disabledMcpjsonServers to avoid re-recommending already-disabled servers

Related Skills

View on GitHub
GitHub Stars2.9k
CategorySecurity
Updated6d ago
Forks289

Languages

JavaScript

Trust signals

88/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 medium