Official agent skill

MCP Audit

by getsentry in getsentry/toolkit

Audit MCP servers for protocol compliance, metadata drift, and compatibility regressions.

OfficialCustom licenceAuto-check passedAgent Workflows

Install MCP Audit

skills CLI
$ npx skills add getsentry/toolkit --skill mcp-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install getsentry/toolkit mcp-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/getsentry/toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/mcp-audit .claude/skills/mcp-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mcp-audit
GitHub stars
917
Token cost
~1.5k tokens
SKILL.md length
655 words
Files
6 (incl. references)
Skills in repo
4
Repo updated
First seen
Licence
Custom licence

At a glance

Audit MCP servers for protocol compliance, metadata drift, and compatibility regressions.

  • Works in 8 steps: Pin the protocol baseline. → Audit lifecycle and capability… → Audit tools if present. → …
  • Reviewing tool annotations
  • SKILL.md covers Workflow and Failure Handling
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

MCP Audit is an agent skill from getsentry/toolkit, published by the product's own GitHub organization. Audit MCP servers for protocol compliance, metadata drift, and compatibility regressions. Use when reviewing tool annotations, tool/result schemas, structured output, lifecycle/init handshake, capabilities, prompts/resources support, transports, auth, security, version drift, or Warden/CI MCP compatibility checks. Trigger phrases include "audit MCP", "check MCP spec compliance", "review tool hints", "validate tools/list", "check initialize handshake", "review prompt or resource capabilities", and "check MCP…

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `SOURCES.md`, `references/checklist.md` and `references/common-findings.md`).

It sits in Agent Workflows, covering MCP servers, Structured output and tool calling and Regulatory compliance. It works with Model Context Protocol. The repository describes itself as: Agentic tooling for Sentry.

When your agent uses it

  • Reviewing tool annotations
  • Tool/result schemas
  • Structured output
  • Lifecycle/init handshake

Example prompts

  • “audit MCP”
  • “check MCP spec compliance”
  • “review tool hints”
  • “/mcp-audit”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Pin the protocol baseline.
  2. Audit lifecycle and capability negotiation.
  3. Audit tools if present.
  4. Audit prompts and resources if present.
  5. Audit transports, auth, and security.
  6. Audit version and compatibility drift.
  7. Run validation.
  8. Report the result.

What it can do on your machine

Read from SKILL.md and the folder at commit 626f869. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

MCP Audit loads about 1.5k tokens when it runs, and up to ~5.3k if it reads all its reference files. Until then it costs about 137 tokens; SKILL.md has 655 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~137
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 655 words (~1,528 tokens).

“Audit an MCP server against the current released MCP specification and any repo-specific compatibility constraints.”

— opening of SKILL.md by getsentry, Custom licence
name
mcp-audit

Read the full SKILL.md on GitHub

Files

SKILL.md and 5 other files (references) in .agents/skills/mcp-audit of getsentry/toolkit.

  • SKILL.md
  • SOURCES.md
  • references/checklist.md
  • references/common-findings.md
  • references/spec-baseline.md
  • references/version-watchpoints.md

Open the folder on GitHubat commit 626f869

Compare with similar skills

MCP Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

MCP Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
MCP Audit this skillgetsentry/toolkit917—~1.5kAutomated safety check: PassCustom licence
Documentation Serverandrea9293/mcp-documentation-server343—~2.3kAutomated safety check: PassMIT
Spring AI MCP Server Patternsgiuseppe-trisciuoglio/developer-kit3551 repos~2.7kAutomated safety check: NotesMIT
MCP Server Builder with mcp-usemcp-use/mcp-use11k—~923Automated safety check: PassApache-2.0
Agent Tool Builderomer-metin/skills-for-antigravity162—~705Automated safety check: PassApache-2.0
Agent Protocolborghei/Claude-Skills874—~1.6kAutomated safety check: PassMIT

Similar skills

  • Documentation Server

    andrea9293/mcp-documentation-server

    A skill your agent uses when you need to store, retrieve, search, or manage documents in a local knowledge base with semantic search and hybrid (vector + full-text) retrieval.

    343 GitHub stars~2.3k tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed
  • Spring AI MCP Server Patterns

    giuseppe-trisciuoglio/developer-kit

    Provides Spring Boot MCP server patterns that create Model Context Protocol servers with Spring AI by defining tool handlers, exposing resources, configuring prompt templates, and setting up…

    355 GitHub starsUsed in 1 repo~2.7k tokens
    Agent WorkflowsAuto-check: notes
  • Builds, modifies, debugs, migrates and verifies TypeScript MCP servers and MCP Apps with the mcp-use framework, treating the installed package's types as the source of truth.

    11k GitHub stars~923 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Agent Tool Builder

    omer-metin/skills-for-antigravity

    Tools are how AI agents interact with the world. An agent skill from omer-metin/skills-for-antigravity.

    162 GitHub stars~705 tokensUpdated 8 mo ago
    AI & LLM EngineeringAuto-check passed
  • Agent Protocol

    borghei/Claude-Skills

    Design AI agent communication protocols: MCP tool schemas, A2A, function calling, and inter- agent messaging.

    874 GitHub stars~1.6k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Ax Gen

    dosco/aithy

    This skill helps an LLM generate correct AxGen code using @ax-llm/ax.

    107 GitHub stars~5.4k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed

More from getsentry/toolkit

  • Logging Observability

    getsentry/toolkit

    Official

    Review code for correct logging and error handling patterns.

    917 GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • MCP QA

    getsentry/toolkit

    Official

    QA MCP tool changes with local CLI and real agent clients. An agent skill from getsentry/toolkit.

    917 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Testing Guidelines

    getsentry/toolkit

    Official

    Guide for writing tests. An agent skill from getsentry/toolkit.

    917 GitHub stars~847 tokensUpdated today
    Auto-check passed

Questions about MCP Audit

What does MCP Audit do?

Audit MCP servers for protocol compliance, metadata drift, and compatibility regressions. MCP Audit is an agent skill from getsentry/toolkit, published by the product's own GitHub organization. Audit MCP servers for protocol compliance, metadata drift, and compatibility regressions.

When should I use MCP Audit?

MCP Audit fits situations like: reviewing tool annotations; tool/result schemas; structured output; lifecycle/init handshake.

How do I install MCP Audit in Claude Code?

Run `npx skills add getsentry/toolkit --skill mcp-audit -a claude-code`. Or copy the skill folder (.agents/skills/mcp-audit in getsentry/toolkit) into .claude/skills/mcp-audit in your project. Claude Code loads it when a task matches its description.

How do I install MCP Audit in Codex?

Run `npx skills add getsentry/toolkit --skill mcp-audit -a codex`. Or copy the skill folder (.agents/skills/mcp-audit in getsentry/toolkit) into .agents/skills/mcp-audit in your project. Codex loads it when a task matches its description.

Can I use MCP Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add getsentry/toolkit --skill mcp-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mcp-audit, .gemini/skills/mcp-audit, .github/skills/mcp-audit and .opencode/skills/mcp-audit in your project.

What does MCP Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: MCP Audit is instructions for the agent only.

Does MCP Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is MCP Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does MCP Audit use?

MCP Audit has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does MCP Audit use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.8k tokens, read only when the agent opens those files.

What are the alternatives to MCP Audit?

Skills that share tags, products or a category with MCP Audit: Documentation Server (andrea9293/mcp-documentation-server, 343 stars), Spring AI MCP Server Patterns (giuseppe-trisciuoglio/developer-kit, 355 stars), MCP Server Builder with mcp-use (mcp-use/mcp-use, 11k stars) and Agent Tool Builder (omer-metin/skills-for-antigravity, 162 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains MCP Audit?

getsentry (a GitHub organization, an official publisher) maintains it in getsentry/toolkit, which has 917 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 7, 2026.

Source: getsentry/toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.