Agent skills and MCP servers are the easiest way to make Claude Code, Codex, Cursor or VS Code more useful. They are also code and instructions written by someone you have never met, running with your files, your terminal and your accounts. Most of them are fine. Some are not, and the ones that are not look exactly like the ones that are until you open them up.
This guide is the check we run before we list anything, written so you can run it yourself in about ten minutes. There is a checklist for each kind that you can tick through as you go. Your ticks are saved in your browser only.
What you are actually installing
An agent skill is a folder with a SKILL.md file in it, plus whatever else
the author put there: reference docs, templates, scripts. Your agent keeps the
skill's short description in view and loads the rest when a task matches. From that
point on, the skill's text is instructions your agent follows, and its scripts
are programs your agent can run, with the same access to your machine as you
have.
So a skill can make your agent do anything your agent can already do: read
files, edit code, run commands, call the network. In Claude Code, a skill can
also list tools in its allowed-tools field, and those
run without asking you for approval
during the turn the skill is used. The docs point out that this applies even in
a folder you have never marked as trusted.
An MCP server is a program that gives your agent new tools, like "list my GitHub issues" or "click this button in the browser". It comes in two shapes:
- Local (stdio). A program on your computer, started by your AI tool,
usually with a command like
npx some-serveroruvx some-server. It runs as you, so it can see whatever you can see. - Remote (HTTP). A server on someone else's machine. It cannot read your disk, but everything your agent sends to it leaves your computer, and it usually holds a token for one of your accounts.
Either way, your agent reads every tool's name and full description to decide when to use it, and reads whatever the tool returns. Both of those are text the server's author controls, and your agent treats that text as context.
Why this is worth ten minutes
This is not a theoretical problem any more.
- In February 2026, Snyk's
ToxicSkills study
scanned 3,984 skills from ClawHub and skills.sh. 534 of them (13.4%) had at
least one critical issue, including malware, prompt injection and exposed
secrets, and a manual review confirmed 76 with malicious payloads. The
techniques included
curl | bashinstalls, password-protected zip downloads, base64-obfuscated code and reading credential files like~/.aws/credentials. - The same month, Koi Security audited all 2,857 skills on ClawHub and found 341 malicious ones, 335 of them from one coordinated campaign it called ClawHavoc. The skills looked professional and had a "Prerequisites" section telling you to install something first. On macOS that something was Atomic Stealer, a commodity info-stealer sold to criminals as a subscription.
- For MCP, Invariant Labs showed
tool poisoning
in April 2025: hidden instructions in a tool's description that the model
sees and you do not, like telling it to read
~/.ssh/id_rsaand pass it along as a "side note". The same write-up describes the "rug pull": a server that changes its tool descriptions after you have approved it. - OWASP now keeps an MCP Top 10, still in beta. Token mismanagement, scope creep, tool poisoning, supply chain attacks and prompt injection through tool output are all on it.
None of this needs you to be careless. It needs you to paste one install command without reading what it installs, which is what a lot of setup guides ask you to do.
Checklist for agent skills
Get the skill onto your disk without installing it, then read it. Cloning the repo gives you the exact files you are going to review, and the commit SHA to pin to afterwards, which cannot change underneath you the way a branch can.
git clone https://github.com/OWNER/REPO.git
cd REPO
git log -1 --format=%H # the commit you are about to readOpen every file in the skill's folder, not just SKILL.md. A quick search
helps you find the lines worth reading twice, but it is not a substitute for
reading: obfuscated content is written to get past exactly this kind of search.
grep -rnE "curl|wget|base64|eval|\.ssh|\.env|\.aws|id_rsa|allowed-tools" path/to/skillAgent skills checklist
0 of 10 checked
Your ticks are saved in this browser only.
Checklist for MCP servers
Start from where the server says it comes from. The official
MCP Registry ties names like
io.github.someone/server to a verified GitHub account or domain, so a listing
there tells you who published it. It does not tell you the code is safe: the
registry says it leaves security scanning to npm, PyPI and Docker Hub and to
the directories built on top of it.
Then read what the model will read. The MCP Inspector lists a server's tools with their full descriptions. It works by starting the server, so do this after you have looked at the code, or inside a container:
npx @modelcontextprotocol/inspector --cli npx -y example-mcp-server@1.4.2 --method tools/listWhen you add the server to your AI tool, pin the exact version you checked rather than letting every restart fetch whatever is newest:
{
"mcpServers": {
"example": {
"command": "npx",
"args": ["-y", "example-mcp-server@1.4.2"]
}
}
}For anything that needs a token, make one just for this server. GitHub, for example, recommends fine-grained tokens limited to the repositories and permissions you actually need. The MCP spec's security best practices make the same point from the other side: a token with broad scopes turns one leak into access to everything.
MCP servers checklist
0 of 11 checked
Your ticks are saved in this browser only.
If you have already installed something dodgy
Do these in order, and do not wait until you are sure. It is much cheaper to rotate a token you did not need to than to find out later that you did.
- Remove it. Delete the skill's folder, or take the server out of your AI tool's MCP config, then restart the tool so it stops loading it.
- Revoke and rotate what it could reach. Every token you gave it, and every
secret it could have read: API keys in
.envfiles, cloud credentials, SSH keys, tokens in your shell profile. Revoke first, then make new ones. - Check what ran. Look through your shell history (
~/.zsh_historyor~/.bash_history) for commands you did not type, and your shell profile files for lines you did not add. - Check your agent's own files. Look for new or changed instructions in
files your agent reads every session, like
CLAUDE.mdorAGENTS.md, and in its memory, if it keeps one. - If you ran an installer it asked for, treat the machine as compromised. A "prerequisite" binary or pasted script is ordinary malware, not an agent problem. Run your security software, change important passwords from a different device, and turn on two-factor authentication where it is not already on.
How we review entries on coding.kitty
Every skill and MCP server in our AI Agents section has passed the checklist above for its kind. Not most of it: all of it. That is our policy, and these are the parts of it that you can check on each page:
- We pin what we reviewed. Skills are pinned to the commit SHA we read, and
MCP servers to an exact package version. The install instructions on each
page use that pin, never a branch or
@latest. - We record when. Every entry shows the date we last ran the checklist on it.
- We re-review. Entries get checked again on a schedule, and always before we move a pin to a newer version.
- We say what it can touch. Each page says in plain words what the skill or server can read and change, and how to give it less.
What we do not do is a full security audit of every line of every server. The checklist catches the problems that have actually been hurting people; it does not prove anything is bug-free. If you spot something we missed, tell us and we will look again.
Browse the reviewed agent skills and MCP servers.
Sources
- Snyk, ToxicSkills: malicious AI agent skills on ClawHub (February 2026)
- The Hacker News, Researchers find 341 malicious ClawHub skills, reporting Koi Security's research (February 2026)
- Invariant Labs, MCP Security Notification: Tool Poisoning Attacks (April 2025)
- OWASP, MCP Top 10
- Model Context Protocol, Security Best Practices and Tools: security considerations
- Model Context Protocol, The MCP Registry
- Claude Code docs, Skills

