Resources

How to Check an Agent Skill or MCP Server Is Safe Before You Install It

A practical checklist for vetting agent skills and MCP servers before you install them: what to read, what to pin, and what to do if one slips through.

coding.kitty9 min read

Agent skills and MCP servers are the easiest way to make Claude Code, Codex, Cursor or VS Code more useful. They are also code and instructions written by someone you have never met, running with your files, your terminal and your accounts. Most of them are fine. Some are not, and the ones that are not look exactly like the ones that are until you open them up.

This guide is the check we run before we list anything, written so you can run it yourself in about ten minutes. There is a checklist for each kind that you can tick through as you go. Your ticks are saved in your browser only.

What you are actually installing

An agent skill is a folder with a SKILL.md file in it, plus whatever else the author put there: reference docs, templates, scripts. Your agent keeps the skill's short description in view and loads the rest when a task matches. From that point on, the skill's text is instructions your agent follows, and its scripts are programs your agent can run, with the same access to your machine as you have.

So a skill can make your agent do anything your agent can already do: read files, edit code, run commands, call the network. In Claude Code, a skill can also list tools in its allowed-tools field, and those run without asking you for approval during the turn the skill is used. The docs point out that this applies even in a folder you have never marked as trusted.

An MCP server is a program that gives your agent new tools, like "list my GitHub issues" or "click this button in the browser". It comes in two shapes:

  • Local (stdio). A program on your computer, started by your AI tool, usually with a command like npx some-server or uvx some-server. It runs as you, so it can see whatever you can see.
  • Remote (HTTP). A server on someone else's machine. It cannot read your disk, but everything your agent sends to it leaves your computer, and it usually holds a token for one of your accounts.

Either way, your agent reads every tool's name and full description to decide when to use it, and reads whatever the tool returns. Both of those are text the server's author controls, and your agent treats that text as context.

Why this is worth ten minutes

This is not a theoretical problem any more.

  • In February 2026, Snyk's ToxicSkills study scanned 3,984 skills from ClawHub and skills.sh. 534 of them (13.4%) had at least one critical issue, including malware, prompt injection and exposed secrets, and a manual review confirmed 76 with malicious payloads. The techniques included curl | bash installs, password-protected zip downloads, base64-obfuscated code and reading credential files like ~/.aws/credentials.
  • The same month, Koi Security audited all 2,857 skills on ClawHub and found 341 malicious ones, 335 of them from one coordinated campaign it called ClawHavoc. The skills looked professional and had a "Prerequisites" section telling you to install something first. On macOS that something was Atomic Stealer, a commodity info-stealer sold to criminals as a subscription.
  • For MCP, Invariant Labs showed tool poisoning in April 2025: hidden instructions in a tool's description that the model sees and you do not, like telling it to read ~/.ssh/id_rsa and pass it along as a "side note". The same write-up describes the "rug pull": a server that changes its tool descriptions after you have approved it.
  • OWASP now keeps an MCP Top 10, still in beta. Token mismanagement, scope creep, tool poisoning, supply chain attacks and prompt injection through tool output are all on it.

None of this needs you to be careless. It needs you to paste one install command without reading what it installs, which is what a lot of setup guides ask you to do.

Checklist for agent skills

Get the skill onto your disk without installing it, then read it. Cloning the repo gives you the exact files you are going to review, and the commit SHA to pin to afterwards, which cannot change underneath you the way a branch can.

git clone https://github.com/OWNER/REPO.git
cd REPO
git log -1 --format=%H   # the commit you are about to read

Open every file in the skill's folder, not just SKILL.md. A quick search helps you find the lines worth reading twice, but it is not a substitute for reading: obfuscated content is written to get past exactly this kind of search.

grep -rnE "curl|wget|base64|eval|\.ssh|\.env|\.aws|id_rsa|allowed-tools" path/to/skill

Agent skills checklist

0 of 10 checked

Who made it

Before reading a line of it, know whose code you are about to run.

What's inside

The part people skip. Read what your agent will read.

What it can reach

Give it the least access that still does the job.

Keeping it that way

What you checked today is only what runs tomorrow if you pin it.

Your ticks are saved in this browser only.

Checklist for MCP servers

Start from where the server says it comes from. The official MCP Registry ties names like io.github.someone/server to a verified GitHub account or domain, so a listing there tells you who published it. It does not tell you the code is safe: the registry says it leaves security scanning to npm, PyPI and Docker Hub and to the directories built on top of it.

Then read what the model will read. The MCP Inspector lists a server's tools with their full descriptions. It works by starting the server, so do this after you have looked at the code, or inside a container:

npx @modelcontextprotocol/inspector --cli npx -y example-mcp-server@1.4.2 --method tools/list

When you add the server to your AI tool, pin the exact version you checked rather than letting every restart fetch whatever is newest:

{
  "mcpServers": {
    "example": {
      "command": "npx",
      "args": ["-y", "example-mcp-server@1.4.2"]
    }
  }
}

For anything that needs a token, make one just for this server. GitHub, for example, recommends fine-grained tokens limited to the repositories and permissions you actually need. The MCP spec's security best practices make the same point from the other side: a token with broad scopes turns one leak into access to everything.

MCP servers checklist

0 of 11 checked

Who made it

Before reading a line of it, know whose code you are about to run.

What's inside

The part people skip. Read what your agent will read.

What it can reach

Give it the least access that still does the job.

Keeping it that way

What you checked today is only what runs tomorrow if you pin it.

Your ticks are saved in this browser only.

If you have already installed something dodgy

Do these in order, and do not wait until you are sure. It is much cheaper to rotate a token you did not need to than to find out later that you did.

  1. Remove it. Delete the skill's folder, or take the server out of your AI tool's MCP config, then restart the tool so it stops loading it.
  2. Revoke and rotate what it could reach. Every token you gave it, and every secret it could have read: API keys in .env files, cloud credentials, SSH keys, tokens in your shell profile. Revoke first, then make new ones.
  3. Check what ran. Look through your shell history (~/.zsh_history or ~/.bash_history) for commands you did not type, and your shell profile files for lines you did not add.
  4. Check your agent's own files. Look for new or changed instructions in files your agent reads every session, like CLAUDE.md or AGENTS.md, and in its memory, if it keeps one.
  5. If you ran an installer it asked for, treat the machine as compromised. A "prerequisite" binary or pasted script is ordinary malware, not an agent problem. Run your security software, change important passwords from a different device, and turn on two-factor authentication where it is not already on.

How we review entries on coding.kitty

Every skill and MCP server in our AI Agents section has passed the checklist above for its kind. Not most of it: all of it. That is our policy, and these are the parts of it that you can check on each page:

  • We pin what we reviewed. Skills are pinned to the commit SHA we read, and MCP servers to an exact package version. The install instructions on each page use that pin, never a branch or @latest.
  • We record when. Every entry shows the date we last ran the checklist on it.
  • We re-review. Entries get checked again on a schedule, and always before we move a pin to a newer version.
  • We say what it can touch. Each page says in plain words what the skill or server can read and change, and how to give it less.

What we do not do is a full security audit of every line of every server. The checklist catches the problems that have actually been hurting people; it does not prove anything is bug-free. If you spot something we missed, tell us and we will look again.

Browse the reviewed agent skills and MCP servers.

Sources

All posts