← ClaudeAtlas

mcp-securitylisted

Audit Model Context Protocol server configurations and apply least-privilege scoping. Covers MCP inventory, capability risk-tiering, secret detection in configuration, malicious or compromised package indicators, and the lifecycle from install through rotation to revocation. Invoke before granting an MCP write access to production, after an MCP security advisory, or as periodic audit.
GoldenWing-360/claude-security-skills · ★ 17 · AI & Automation · score 75
Install: claude install-skill GoldenWing-360/claude-security-skills
# MCP Security The Model Context Protocol turns an LLM into a system that can **act**. That makes every MCP server a new piece of attack surface, with three properties that classical security tooling does not yet handle well: 1. **Capability creep** — adding an MCP often adds dozens of tools at once. Most users never read what they granted. 2. **LLM as confused deputy** — the LLM will happily call any tool that fits the conversational context, including ones the user did not mean to invoke. 3. **Cross-MCP attacks** — one MCP can return data that triggers another MCP to act (indirect prompt injection across the tool boundary). This skill is the audit/hardening counterpart to [`ai-agent-guardrails`](../ai-agent-guardrails/SKILL.md) and [`prompt-injection-defense`](../prompt-injection-defense/SKILL.md). ## When to invoke - A new MCP server is being installed - An MCP advisory or version bump landed - A contractor's or shared machine needs an audit - An LLM agent made a write you did not expect — start here to scope what it *could* have done - Periodic re-audit (monthly is reasonable for active stacks) ## Step 1 — Inventory MCP config can live in several places. Find them all. ```bash # Claude Code / claude-desktop / cursor / windsurf — common locations ls -la ~/.claude/mcp.json ~/.claude/settings.json 2>/dev/null ls -la ~/Library/Application\ Support/Claude/claude_desktop_config.json 2>/dev/null ls -la ~/.cursor/mcp.json ~/.codeium/windsurf/mcp_config.json 2>/dev/null #