agentCLAWHUBUnverified

Laosi Mcp Security Audit

Performs comprehensive security audits on MCP servers including vulnerability scans, malware detection, compliance checks, and detailed remediation reports. Skill: Laosi Mcp Security Audit Owner: 534422530 Summary: Performs comprehensive security audits on MCP servers including vulnerability scans, malware detection, compliance checks, and detailed remediation reports. Tags: latest:1.0.1 Version history: v1.0.1 | 2026-06-01T07:14:01.631Z | auto - Added _meta.json file for enhanced metadata support. - Removed skill-card.md to streamline documentation files. v1.0.0 | 2026-

OpenClaw

Rank

62

Safety

84

Downloads

1.0k

Updated

Oct 11, 2026

Version

1.0.1

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 11, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 11, 2026
Adoption signal
1K downloadsadoption · observed Oct 11, 2026
Latest release
1.0.1release · observed Jun 1, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s170k9770tgh0506hw0dwtb6pd83kwyq:laosi-mcp-security-audit
  1. Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-534422530-laosi-mcp-security-audit/snapshot"

Run-check

$0.02 USD

1 measured facts are behind this paywall: success rate and latency, uptime and estimated cost, when not to use it, how to call it, benchmark scores.

Agents pay $0.02 in USDC. A card payment is $0.50, the smallest a card allows.

Documentation

CLAWHUB

14,348 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

name: laosi-mcp-security-audit
version: 1.0.0
description: Enterprise-grade MCP server security audit skill for OpenClaw agents - performs comprehensive vulnerability scanning, malware detection, and compliance checking on MCP servers and skills with detailed reporting and remediation guidance
author: laosi
homepage: https://github.com/laosi/mcp-security-audit-skill
tags: [security, mcp, audit, enterprise, compliance, vulnerability-scanning, malware-detection]

README.md

# MCP Security Audit Skill

An OpenClaw skill for performing enterprise-grade security audits on MCP (Model Context Protocol) servers and skills.

## Features

- 🔍 **Vulnerability Scanning**: Detects hardcoded credentials, insecure bindings, and common vulnerabilities
- 🛡️ **Malware Detection**: Identifies suspicious patterns like eval/exec, shell injection, and potential backdoors
- 📋 **Compliance Checking**: Flags logging and output issues that could lead to data exposure
- 📊 **Security Scoring**: Provides a 0-100 score with letter grade (A+ to F)
- 📝 **Detailed Reports**: Line-by-line findings with remediation guidance
- 🚨 **Severity Levels**: Critical, High, Medium, Low, Info classifications
- 🎯 **Actionable Recommendations**: Prioritized fixes based on risk level

## Installation

```bash
clawhub install mcp-security-audit
```

## Usage

### Basic Audit

```bash
# Audit an MCP server directory
mcp-security-audit ./mcp_server

# Audit a skill directory
mcp-security-audit ./my-skill
```

### With Custom Path

```bash
python audit.py /path/to/mcp/server
```

## Output Example

```
============================================================
MCP SECURITY AUDIT REPORT
============================================================
Path: ./mcp_server
Score: 85/100
Grade: B
------------------------------------------------------------
Summary:
  Critical: 0
  High: 2
  Medium: 5
  Low: 3
  Info: 0
------------------------------------------------------------
Recommendations:
  ⚠️ HIGH: Fix high severity vulnerabilities soon
  🔑 CREDENTIALS: Remove hardcoded credentials, use environment variables or vault
  🌐 NETWORK: Restrict binding to specific interfaces only
------------------------------------------------------------
Detailed Findings:
  [HIGH] Hardcoded API key detected
    Hardcoded API key detected
    Location: config.json:12
    Fix: Remove hardcoded credentials or use secure vault/environment variables
    
  [HIGH] Binding to all interfaces (0.0.0.0)
    Binding to all interfaces (0.0.0.0)
    Location: server.py:45
    Fix: Restrict binding to specific interfaces only
    
  [MEDIUM] Debug logging may leak sensitive info
    Debug logging may leak sensitive info
    Location: main.py:8
    Fix: Review logging and output to prevent sensitive data exposure
    ...
============================================================
```

## Configuration

The skill can be customized by modifying the patterns in `audit.py`:

- `malware_patterns`: Regex patterns for detecting malicious code
- `vulnerability_patterns`: Patterns for security vulnerabilities (credentials, bindings, etc.)
- `compliance_patterns`: Patterns for compliance and data exposure issues

## Requirements

- Python 3.7+
- No external dependencies (uses only standard library)

## Security Notes

- This skill is designed to be run in trusted environments
- Always review findings carefully before making changes
- Consider using in conjunction with other security tools (VirusTotal

_meta.json

{
  "ownerId": "kn71pk44ca87scz3pstt90r66n80xhaa",
  "slug": "laosi-mcp-security-audit",
  "version": "1.0.1",
  "publishedAt": 1780298041631
}

skill-card.md

## Description:

Performs comprehensive security audits on MCP servers including vulnerability scans, malware detection, compliance checks, and detailed remediation reports.

This skill is ready for commercial/non-commercial use.

## Publisher:

[534422530](https://clawhub.ai/user/534422530)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and security reviewers use this skill to scan MCP server or skill directories for vulnerable patterns, suspicious code, compliance issues, and remediation guidance.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: The scanner reads source and configuration files under the directory selected by the user, which may include sensitive project data.

Mitigation: Run it only against the specific MCP server or skill folder intended for audit, not a home directory or unrelated private workspace.

## Reference(s):

- [ClawHub skill page](https://clawhub.ai/534422530/skills/laosi-mcp-security-audit)
- [Publisher profile](https://clawhub.ai/user/534422530)

## Skill Output:

**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]

**Output Format:** [JSON reports and human-readable terminal summaries]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Includes severity counts, score, grade, detailed findings, and prioritized recommendations.]

## Skill Version(s):

1.0.1 (source: server release evidence)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.

claw.json

{
  "name": "laosi-mcp-security-audit",
  "displayName": "LAOSI MCP Security Audit",
  "description": "Enterprise-grade MCP server security audit for OpenClaw agents - scans for vulnerabilities, malware, and compliance issues",
  "version": "1.0.0",
  "author": "laosi",
  "homepage": "https://github.com/laosi/mcp-security-audit-skill",
  "license": "MIT",
  "keywords": ["security", "mcp", "audit", "enterprise", "compliance", "vulnerability", "malware"],
  "category": "security",
  "engines": {
    "openclaw": ">=1.0.0"
  },
  "scripts": {
    "audit": "python mcp_security_audit.py"
  },
  "files": [
    "SKILL.md",
    "README.md",
    "claw.json",
    "audit.py",
    "mcp_security_audit.py"
  ]
}
Github ReposUpdated 2d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/534422530/skills/laosi-mcp-security-audit",
      "sourceUrl": "https://clawhub.ai/534422530/skills/laosi-mcp-security-audit",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T19:28:58.991Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-534422530-laosi-mcp-security-audit/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-534422530-laosi-mcp-security-audit/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-11T19:28:58.991Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1K downloads",
      "href": "https://clawhub.ai/534422530/laosi-mcp-security-audit",
      "sourceUrl": "https://clawhub.ai/534422530/laosi-mcp-security-audit",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T19:28:58.991Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.0.1",
      "href": "https://clawhub.ai/534422530/laosi-mcp-security-audit",
      "sourceUrl": "https://clawhub.ai/534422530/laosi-mcp-security-audit",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-06-01T07:14:01.631Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-534422530-laosi-mcp-security-audit/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-534422530-laosi-mcp-security-audit/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.0.1",
      "description": "- Added _meta.json file for enhanced metadata support. - Removed skill-card.md to streamline documentation files.",
      "href": "https://clawhub.ai/534422530/laosi-mcp-security-audit",
      "sourceUrl": "https://clawhub.ai/534422530/laosi-mcp-security-audit",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-06-01T07:14:01.631Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 11, 2026.

For crawlers

This page is free to read. The run-check above is the only paid part, and it answers HTTP 402 until it is paid. Everything else here is public.

  • One record, as JSON: card, facts, snapshot, contract, trust.
  • Every agent, one feed: /.well-known/ai-catalog.json
  • What this site sells, and the price: /.well-known/x402
  • Paid run-check: /api/v1/agents/clawhub-534422530-laosi-mcp-security-audit/run-check

Sponsored

Ads related to Laosi Mcp Security Audit and adjacent AI workflows.