Agent skill

Audit Hosting

by hostinger in hostinger/api-mcp-server

Audit a Hostinger web hosting account (Shared, Cloud and Agency plans) and report what needs attention: every plan and website, SSL problems, broken or vulnerable WordPress installs, failed Node.js…

MITAuto-check passedProductivity & Automation

Install Audit Hosting

skills CLI
$ npx skills add hostinger/api-mcp-server --skill audit-hosting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hostinger/api-mcp-server audit-hosting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hostinger/api-mcp-server.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/audit-hosting .claude/skills/audit-hosting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-hosting
GitHub stars
159
Token cost
~1.4k tokens
SKILL.md length
499 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Audit a Hostinger web hosting account (Shared, Cloud and Agency plans) and report what needs attention: every plan and website, SSL problems, broken or vulnerable WordPress installs, failed Node.js…

  • Works in 3 steps: Inventory → Checks → Report
  • Productivity & Automation work in your project
  • SKILL.md covers Calling the operations, 1. Inventory, 2. Checks and 3. Report, plus 1 more section
  • Calls curl

What it does

Audit Hosting is an agent skill from hostinger/api-mcp-server. Audit a Hostinger web hosting account (Shared, Cloud and Agency plans) and report what needs attention: every plan and website, SSL problems, broken or vulnerable WordPress installs, failed Node.js builds and vulnerable npm packages, databases and Agency Plan orders near their limits, and hosting plans about to lapse. Read-only; produces a prioritised to-do list and names the skill that fixes each item. Triggers: what do I have on Hostinger, audit my hosting, check all my websites, what needs attention, health…

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation. It works with Node.js, WordPress and npm. The licence is MIT.

When your agent uses it

  • Productivity & Automation work in your project

Example prompts

  • “/audit-hosting”

Requirements

  • Node.js

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Inventory
  2. Checks
  3. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 6c3b1a1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Hosting loads about 1.4k tokens when it runs. Until then it costs about 151 tokens; SKILL.md has 499 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~151
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hostinger/api-mcp-server at commit 6c3b1a1, republished under its MIT licence (© hostinger). 499 words, ~1,360 tokens.

Download SKILL.mdSave it as .claude/skills/audit-hosting/SKILL.md (or your agent's skills folder).
name
audit-hosting
description
Audit a Hostinger web hosting account (Shared, Cloud and Agency plans) and report what needs attention: every plan and website, SSL problems, broken or vulnerable WordPress installs, failed Node.js builds and vulnerable npm packages, databases and Agency Plan orders near their limits, and hosting plans about to lapse. Read-only; produces a prioritised to-do list and names the skill that fixes each item. Triggers: what do I have on Hostinger, audit my hosting, check all my websites, what needs attention, health check my sites, are any of my sites broken, which of my sites are insecure.

Audit hosting

Read-only from start to finish. The output is a report; every fix is a separate, confirmed step through another skill.

Calling the operations

  • Read the inputSchema that search returns before the first call of each operation. If a name below is rejected as unknown, search for what the step does (e.g. "ssl status").
  • Batch reads with multi-execute, up to 20 steps a batch. Batches chain operations from one server only — the Hostinger Connector runs hosting, wordpress, agency-hosting and billing as separate servers. When a product group is switched off, skip its checks and say which were skipped.
  • Page every list until meta.total is covered.
  • Leave hosting_php_get out — it is large and says nothing about account health.

1. Inventory

One batch per server:

  • hosting_orders_list with statuses: ["active", "suspended"]. cloud_* plan names are Cloud; the rest (hostinger_premium_*, hostinger_business_*, …) are Shared.
  • hosting_websites_list — every Shared and Cloud website with website_type, username, order_id and is_enabled (false means suspended).
  • wordpress_installations_list with ownership: "all" — id, is_valid, validation_error.
  • agency-hosting_orders_list and agency-hosting_websites_list-plan — Agency orders and sites (details.uid, details.type, details.domains, details.state).

Tell the user the size (plans, websites, WordPress installs) before the checks. For large accounts offer to scope the audit to one order or domain.

2. Checks

Per Shared and Cloud website (skip builder and horizons):

  • hosting_ssl_status — flag failed (with last_error), expired, not_installed on a custom domain, is_https_redirect_enabled: false, and expires_at within 30 days when is_lifetime is false. Lifetime certificates renew on their own.
  • Node.js sites: hosting_nodejs_list-builds with per_page: 1 (latest build failed?) and hosting_nodejs_list-vulnerabilities with severities: ["critical", "high"].

Per hosting account (username): hosting_databases_list — flag disk_usage_mb above 80% of max_size_mb.

Per WordPress install: wordpress_installations_show-core-version (core vulnerabilities) and wordpress_plugins_list-installed (vulnerable plugins and pending updates).

Per Agency order: agency-hosting_metrics_list-order-resource-usage with time_frame_hours: 168 and agency-hosting_metrics_list-plan-order-disk-usage with time_frame_days: 7 — flag usage above 80% of the plan quota and name the heaviest websites.

Per Agency site: agency-hosting_ssl_website-status for each custom domain in details.domains; flag details.state other than active.

Plans about to lapse (billing product): billing_subscriptions_list, joined to hosting orders on subscription_id — flag not_renewing, or is_auto_renewed: false with expires_at within 30 days. Every site on that plan goes down with it.

From outside, for each custom domain:

bash
curl -sS -o /dev/null -w "%{http_code}\n" --max-time 15 https://DOMAIN/
curl -sSI --max-time 15 https://DOMAIN/ | grep -i "^platform"

No platform: hostinger header means the domain does not reach this hosting.

Show full SKILL.md (133 more words)Show less

3. Report

# Hosting audit
3 plans (2 Shared, 1 Cloud) + 1 Agency · 14 websites (6 WordPress, 3 Node.js, 5 other) · 4 Agency sites

## Fix now
- shop.example.com — latest Node.js build failed 2 days ago → troubleshoot-website
- blog.example.com — contact-form-x 5.2 has a known vulnerability, fixed in 5.3 → maintain-wordpress

## Soon
- example.org — Business plan expires in 12 days, auto-renew off → renew in hPanel
- Agency order 1000000001 — 86% of disk quota, mostly client-a.com

## Worth knowing
- 4 WordPress installs have pending plugin updates → maintain-wordpress

## Healthy
docs.example.com, portfolio.example.com, …
  • Fix now: site down or not reaching Hostinger, failed latest build, invalid WordPress install, SSL failed or expired, critical vulnerabilities, suspended website.
  • Soon: high vulnerabilities, a plan lapsing within 30 days, usage above 80% of a quota, HTTPS redirect off, non-lifetime certificates expiring.
  • Worth knowing: pending updates, inactive plugins with vulnerabilities.

Each item names the evidence and the skill that fixes it: troubleshoot-website, maintain-wordpress, connect-domain or deploy-to-hosting. Patchable npm vulnerabilities on GitHub-deployed sites can be fixed with hosting_nodejs_patch-vulnerabilities, which opens a pull request — offer it, do not run it as part of the audit.

Not available through the API

CPU and memory usage for Shared and Cloud plans, website backup status, and PHP error logs. Mention them once at the end so the user knows what the audit could not see.

© hostinger, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/audit-hosting of hostinger/api-mcp-server.

Open the folder on GitHubat commit 6c3b1a1

Compare with similar skills

Audit Hosting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Hosting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Hosting this skillhostinger/api-mcp-server159—~1.4kAutomated safety check: PassMIT
Chrome CDP Browser Controlzenstory-ai/oh-story-claudecode7.4k3 repos~1.2kAutomated safety check: PassMIT
Javascript SDKaiskillstore/marketplace4301 repos~3.3kAutomated safety check: PassNone
EasyEDA Pro API Bridgeeasyeda/easyeda-api-skill861—~7.8kAutomated safety check: PassMIT
TeamAI Team SyncTencent/teamai-cli5.1k—~632Automated safety check: PassCustom licence
Reflexo ReleaseMyriad-Dreamin/typst.ts1.2k—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • Chrome CDP Browser Control

    zenstory-ai/oh-story-claudecode

    Drives a Chrome window over the DevTools Protocol with the agent-browser CLI, so the agent can reuse your logged-in sessions, read pages and pull tokens.

    7.4k GitHub starsUsed in 3 repos~1.2k tokens
    Productivity & AutomationAuto-check passed
  • Javascript SDK

    aiskillstore/marketplace

    JavaScript/TypeScript SDK for inference.sh - run AI apps, build agents, integrate with all models.

    430 GitHub starsUsed in 1 repo~3.3k tokens
    Backend & APIsAuto-check passed
  • EasyEDA Pro API Bridge

    easyeda/easyeda-api-skill

    Gives an agent the EasyEDA Pro API reference and a WebSocket bridge to run code in a live EasyEDA client, for PCB, schematic and library work and extension development.

    861 GitHub stars~7.8k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • TeamAI Team Sync

    Tencent/teamai-cli

    Make every team AI native — TeamAI syncs a team's AI skills, rules, docs and env across AI coding tools. Use when the task operates on team-shared AI…

    5.1k GitHub stars~632 tokensUpdated yesterday
    Knowledge ManagementAuto-check passed
  • Reflexo Release

    Myriad-Dreamin/typst.ts

    Guide Reflexo/typst.ts release preparation and operator handoffs.

    1.2k GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed

More from hostinger/api-mcp-server

All 8 skills in this repo
  • Connect Domain

    hostinger/api-mcp-server

    Connect a custom domain to a website on Hostinger web hosting (Shared, Cloud or Agency plans) end to end: attach the domain to the site, point DNS at Hostinger without breaking existing email or…

    159 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Deploy To Hosting

    hostinger/api-mcp-server

    Deploy an existing project to a website on Hostinger web hosting (Shared, Cloud or Agency plans) and keep it deployed: picks the right deploy for static sites, Node.js apps (Next.js, Nuxt, Express…

    159 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check: notes
  • Hostinger Headless Entry

    hostinger/api-mcp-server

    Build a complete website on Hostinger from a single prompt — hosting, domain, and (optionally) a store with real checkout or a blog/CMS the owner edits in WordPress.

    159 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Maintain Wordpress

    hostinger/api-mcp-server

    Keep WordPress sites on Hostinger web hosting updated and secure: checks core, plugin and theme versions, known vulnerabilities and install health on one site or every site in the account, reports…

    159 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Migrate To Hosting

    hostinger/api-mcp-server

    Move an existing website from another host to Hostinger web hosting (Shared, Cloud or Agency plans) without downtime: WordPress sites from a files archive and SQL dump, static and PHP sites from an…

    159 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Troubleshoot Website

    hostinger/api-mcp-server

    Diagnose and fix a website on Hostinger web hosting (Shared, Cloud or Agency plans) that is down, slow, erroring, insecure or failing to build.

    159 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Questions about Audit Hosting

What does Audit Hosting do?

Audit a Hostinger web hosting account (Shared, Cloud and Agency plans) and report what needs attention: every plan and website, SSL problems, broken or vulnerable WordPress installs, failed Node.js…. Audit Hosting is an agent skill from hostinger/api-mcp-server.js builds and vulnerable npm packages, databases and Agency Plan orders near their limits, and hosting plans about to lapse.

When should I use Audit Hosting?

Audit Hosting fits situations like: productivity & Automation work in your project.

How do I install Audit Hosting in Claude Code?

Run `npx skills add hostinger/api-mcp-server --skill audit-hosting -a claude-code`. Or copy the skill folder (skills/audit-hosting in hostinger/api-mcp-server) into .claude/skills/audit-hosting in your project. Claude Code loads it when a task matches its description.

How do I install Audit Hosting in Codex?

Run `npx skills add hostinger/api-mcp-server --skill audit-hosting -a codex`. Or copy the skill folder (skills/audit-hosting in hostinger/api-mcp-server) into .agents/skills/audit-hosting in your project. Codex loads it when a task matches its description.

Can I use Audit Hosting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hostinger/api-mcp-server --skill audit-hosting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-hosting, .gemini/skills/audit-hosting, .github/skills/audit-hosting and .opencode/skills/audit-hosting in your project.

What does Audit Hosting need to run?

Going by SKILL.md and its folder, Audit Hosting needs the command-line tools its instructions call (curl). Our summary lists: Node.js.

Does Audit Hosting access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit Hosting safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Hosting use?

Audit Hosting is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Hosting use?

About 1.4k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Hosting?

Skills that share tags, products or a category with Audit Hosting: Chrome CDP Browser Control (zenstory-ai/oh-story-claudecode, 7.4k stars), Javascript SDK (aiskillstore/marketplace, 430 stars), EasyEDA Pro API Bridge (easyeda/easyeda-api-skill, 861 stars) and TeamAI Team Sync (Tencent/teamai-cli, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Hosting?

hostinger (a GitHub organization) maintains it in hostinger/api-mcp-server, which has 159 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 7, 2026.

Source: hostinger/api-mcp-server on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.