Laosi Mcp Security Audit
Performs comprehensive security audits on MCP servers including vulnerability scans, malware detection, compliance checks, and detailed remediation reports. Skill: Laosi Mcp Security Audit Owner: 534422530 Summary: Performs comprehensive security audits on MCP servers including vulnerability scans, malware detection, compliance checks, and detailed remediation reports. Tags: latest:1.0.1 Version history: v1.0.1 | 2026-06-01T07:14:01.631Z | auto - Added _meta.json file for enhanced metadata support. - Removed skill-card.md to streamline documentation files. v1.0.0 | 2026-
Rank
62
Safety
84
Downloads
1.0k
Updated
Oct 11, 2026
Version
1.0.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1K downloadsadoption · observed Oct 11, 2026
- Latest release
- 1.0.1release · observed Jun 1, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s170k9770tgh0506hw0dwtb6pd83kwyq:laosi-mcp-security-audit- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-534422530-laosi-mcp-security-audit/snapshot"
Run-check
$0.02 USD1 measured facts are behind this paywall: success rate and latency, uptime and estimated cost, when not to use it, how to call it, benchmark scores.
Agents pay $0.02 in USDC. A card payment is $0.50, the smallest a card allows.
Documentation
CLAWHUB
14,348 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
name: laosi-mcp-security-audit version: 1.0.0 description: Enterprise-grade MCP server security audit skill for OpenClaw agents - performs comprehensive vulnerability scanning, malware detection, and compliance checking on MCP servers and skills with detailed reporting and remediation guidance author: laosi homepage: https://github.com/laosi/mcp-security-audit-skill tags: [security, mcp, audit, enterprise, compliance, vulnerability-scanning, malware-detection]
README.md
# MCP Security Audit Skill
An OpenClaw skill for performing enterprise-grade security audits on MCP (Model Context Protocol) servers and skills.
## Features
- 🔍 **Vulnerability Scanning**: Detects hardcoded credentials, insecure bindings, and common vulnerabilities
- 🛡️ **Malware Detection**: Identifies suspicious patterns like eval/exec, shell injection, and potential backdoors
- 📋 **Compliance Checking**: Flags logging and output issues that could lead to data exposure
- 📊 **Security Scoring**: Provides a 0-100 score with letter grade (A+ to F)
- 📝 **Detailed Reports**: Line-by-line findings with remediation guidance
- 🚨 **Severity Levels**: Critical, High, Medium, Low, Info classifications
- 🎯 **Actionable Recommendations**: Prioritized fixes based on risk level
## Installation
```bash
clawhub install mcp-security-audit
```
## Usage
### Basic Audit
```bash
# Audit an MCP server directory
mcp-security-audit ./mcp_server
# Audit a skill directory
mcp-security-audit ./my-skill
```
### With Custom Path
```bash
python audit.py /path/to/mcp/server
```
## Output Example
```
============================================================
MCP SECURITY AUDIT REPORT
============================================================
Path: ./mcp_server
Score: 85/100
Grade: B
------------------------------------------------------------
Summary:
Critical: 0
High: 2
Medium: 5
Low: 3
Info: 0
------------------------------------------------------------
Recommendations:
⚠️ HIGH: Fix high severity vulnerabilities soon
🔑 CREDENTIALS: Remove hardcoded credentials, use environment variables or vault
🌐 NETWORK: Restrict binding to specific interfaces only
------------------------------------------------------------
Detailed Findings:
[HIGH] Hardcoded API key detected
Hardcoded API key detected
Location: config.json:12
Fix: Remove hardcoded credentials or use secure vault/environment variables
[HIGH] Binding to all interfaces (0.0.0.0)
Binding to all interfaces (0.0.0.0)
Location: server.py:45
Fix: Restrict binding to specific interfaces only
[MEDIUM] Debug logging may leak sensitive info
Debug logging may leak sensitive info
Location: main.py:8
Fix: Review logging and output to prevent sensitive data exposure
...
============================================================
```
## Configuration
The skill can be customized by modifying the patterns in `audit.py`:
- `malware_patterns`: Regex patterns for detecting malicious code
- `vulnerability_patterns`: Patterns for security vulnerabilities (credentials, bindings, etc.)
- `compliance_patterns`: Patterns for compliance and data exposure issues
## Requirements
- Python 3.7+
- No external dependencies (uses only standard library)
## Security Notes
- This skill is designed to be run in trusted environments
- Always review findings carefully before making changes
- Consider using in conjunction with other security tools (VirusTotal_meta.json
{
"ownerId": "kn71pk44ca87scz3pstt90r66n80xhaa",
"slug": "laosi-mcp-security-audit",
"version": "1.0.1",
"publishedAt": 1780298041631
}skill-card.md
## Description: Performs comprehensive security audits on MCP servers including vulnerability scans, malware detection, compliance checks, and detailed remediation reports. This skill is ready for commercial/non-commercial use. ## Publisher: [534422530](https://clawhub.ai/user/534422530) ### License/Terms of Use: MIT-0 ## Use Case: Developers and security reviewers use this skill to scan MCP server or skill directories for vulnerable patterns, suspicious code, compliance issues, and remediation guidance. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The scanner reads source and configuration files under the directory selected by the user, which may include sensitive project data. Mitigation: Run it only against the specific MCP server or skill folder intended for audit, not a home directory or unrelated private workspace. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/534422530/skills/laosi-mcp-security-audit) - [Publisher profile](https://clawhub.ai/user/534422530) ## Skill Output: **Output Type(s):** [text, markdown, code, shell commands, configuration, guidance] **Output Format:** [JSON reports and human-readable terminal summaries] **Output Parameters:** [1D] **Other Properties Related to Output:** [Includes severity counts, score, grade, detailed findings, and prioritized recommendations.] ## Skill Version(s): 1.0.1 (source: server release evidence) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
claw.json
{
"name": "laosi-mcp-security-audit",
"displayName": "LAOSI MCP Security Audit",
"description": "Enterprise-grade MCP server security audit for OpenClaw agents - scans for vulnerabilities, malware, and compliance issues",
"version": "1.0.0",
"author": "laosi",
"homepage": "https://github.com/laosi/mcp-security-audit-skill",
"license": "MIT",
"keywords": ["security", "mcp", "audit", "enterprise", "compliance", "vulnerability", "malware"],
"category": "security",
"engines": {
"openclaw": ">=1.0.0"
},
"scripts": {
"audit": "python mcp_security_audit.py"
},
"files": [
"SKILL.md",
"README.md",
"claw.json",
"audit.py",
"mcp_security_audit.py"
]
}AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/534422530/skills/laosi-mcp-security-audit",
"sourceUrl": "https://clawhub.ai/534422530/skills/laosi-mcp-security-audit",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T19:28:58.991Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-534422530-laosi-mcp-security-audit/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-534422530-laosi-mcp-security-audit/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T19:28:58.991Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1K downloads",
"href": "https://clawhub.ai/534422530/laosi-mcp-security-audit",
"sourceUrl": "https://clawhub.ai/534422530/laosi-mcp-security-audit",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T19:28:58.991Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.0.1",
"href": "https://clawhub.ai/534422530/laosi-mcp-security-audit",
"sourceUrl": "https://clawhub.ai/534422530/laosi-mcp-security-audit",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-06-01T07:14:01.631Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-534422530-laosi-mcp-security-audit/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-534422530-laosi-mcp-security-audit/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.0.1",
"description": "- Added _meta.json file for enhanced metadata support. - Removed skill-card.md to streamline documentation files.",
"href": "https://clawhub.ai/534422530/laosi-mcp-security-audit",
"sourceUrl": "https://clawhub.ai/534422530/laosi-mcp-security-audit",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-06-01T07:14:01.631Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
For crawlers
This page is free to read. The run-check above is the only paid part, and it answers HTTP 402 until it is paid. Everything else here is public.
- One record, as JSON: card, facts, snapshot, contract, trust.
- Every agent, one feed: /.well-known/ai-catalog.json
- What this site sells, and the price: /.well-known/x402
- Paid run-check: /api/v1/agents/clawhub-534422530-laosi-mcp-security-audit/run-check
