CtrlK
BlogDocsLog inGet started
Tessl Logo

mcp-server-review

Security review of MCP (Model Context Protocol) server implementations and configurations. Use when auditing MCP server source code, evaluating third-party MCP servers before installation, or reviewing Claude Code MCP integrations for overpermissioning, injection risks, and data exposure.

67

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, well-sequenced security-audit checklist with concrete per-step checks and no concept padding. Its main weakness is that it defers the detailed procedure and finding template to bundle files that are not present, leaving the references dangling.

Suggestions

Ship the referenced bundle files `plays/mcp-server-review.md` and `templates/finding.md`, or inline the full procedure so the skill is self-contained.

Add a validation/triage step (e.g., confirm each finding is reproducible and assign severity before writing it up) to give the workflow an explicit checkpoint.

Make the supply-chain step actionable by naming a concrete SCA command or tool instead of "run SCA on dependencies".

DimensionReasoningScore

Conciseness

Lean checklist with no concept padding — it assumes Claude knows TLS, SSRF, and SCA, and every parenthetical ("stdio vs HTTP/SSE", "../ in file paths", "169.254.169.254") is a concrete example that earns its place.

5 / 5

Actionability

Concrete, specific checks (command injection via shell interpolation, path traversal via ../, unparameterized SQL, SSRF) and a clear risk taxonomy (READ-ONLY/MUTATION/DESTRUCTIVE/NETWORK/CREDENTIAL-ACCESS), but "run SCA on dependencies" names no tool and the "full procedure" is deferred to a missing file.

4 / 5

Workflow Clarity

Seven clearly sequenced, numbered steps each containing explicit sub-checks; minor gap is the absence of a finding-triage/validation checkpoint to confirm findings and calibrate severity before output.

4 / 5

Progressive Disclosure

Sections are well-organized and references are inline-signaled, but both referenced paths (`plays/mcp-server-review.md`, `templates/finding.md`) do not exist as bundle files — the "full procedure" the body defers to is missing, breaking navigation.

3 / 5

Total

16

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly states both capability and trigger conditions with concrete MCP-audit scenarios and named risk categories. Third-person voice is used correctly and trigger guidance is explicit.

DimensionReasoningScore

Specificity

Lists several concrete actions — "auditing MCP server source code", "evaluating third-party MCP servers before installation", "reviewing ... integrations for overpermissioning, injection risks, and data exposure" — with named risk categories; minor coverage gaps keep it just below comprehensive.

4 / 5

Completeness

Explicitly answers both what ("Security review of MCP server implementations and configurations") and when ("Use when auditing ... evaluating ... or reviewing ...") with three concrete trigger scenarios, matching the score-5 anchor pattern.

5 / 5

Trigger Term Quality

Natural trigger terms a user would say are present ("MCP server", "third-party MCP servers", "Claude Code MCP integrations", "auditing", "injection risks", "data exposure") plus the spelled-out "Model Context Protocol"; a few natural synonyms (e.g., mcp.json, config file) are missing.

4 / 5

Distinctiveness Conflict Risk

Clear MCP-specific niche with distinct triggers ("MCP server", "Claude Code MCP integrations"); minor overlap risk with the closely related general security-review skill when a request is phrased generically.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
OWASP/secure-agent-playbook
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.