Agent skill

Review Security Report

by PrefectHQ in PrefectHQ/fastmcp

Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them.

Apache-2.0Auto-check passedSecurity

Install Review Security Report

skills CLI
$ npx skills add PrefectHQ/fastmcp --skill review-security-report -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PrefectHQ/fastmcp review-security-report --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PrefectHQ/fastmcp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/review-security-report .claude/skills/review-security-report && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-security-report
GitHub stars
28k
Token cost
~1.2k tokens
SKILL.md length
585 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
Apache-2.0

At a glance

Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them.

  • Works in 3 steps: What FastMCP promises for the exact… → Whether the proof of concept bypasses,… → Whether the behavior follows the…
  • Security advisories
  • SKILL.md covers Preserve the evidence, Reproduce the claim, Identify the responsible layer and Establish FastMCP's contract, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Review Security Report is an agent skill from PrefectHQ/fastmcp. Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them. Use for security advisories, bug-bounty submissions, OAuth or MCP vulnerability claims, and proposed security fixes.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering MCP servers, OAuth and OpenID Connect and Bug bounty. It works with Model Context Protocol. The repository describes itself as: 🚀 The fast, Pythonic way to build MCP servers and clients. The licence is Apache-2.0.

When your agent uses it

  • Security advisories
  • Bug-bounty submissions
  • MCP vulnerability claims
  • Proposed security fixes

Example prompts

  • “/review-security-report”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. What FastMCP promises for the exact configuration, supported API, and affected releases.
  2. Whether the proof of concept bypasses, disables, or delegates that protection.
  3. Whether the behavior follows the implemented protocol despite any stricter FastMCP promise.

What it can do on your machine

Read from SKILL.md and the folder at commit e2fcc41. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Security Report loads about 1.2k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 585 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PrefectHQ/fastmcp at commit e2fcc41, republished under its Apache-2.0 licence (© PrefectHQ). 585 words, ~1,169 tokens.

Download SKILL.mdSave it as .claude/skills/review-security-report/SKILL.md (or your agent's skills folder).
name
review-security-report
description
Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them. Use for security advisories, bug-bounty submissions, OAuth or MCP vulnerability claims, and proposed security fixes.

Review a FastMCP security report

A working proof of concept establishes behavior, not ownership or classification. Identify the component that violates a promised security boundary before changing code or advisory state.

Preserve the evidence

Before editing an advisory, export the report, comments, proof of concept, configuration, and claimed affected versions. Record the reproduced commit and derive affected releases from history.

Keep the investigation read-only until classification. Do not mutate the advisory or prepare a fix merely because the proof of concept works.

Reproduce the claim

Use the smallest end-to-end reproduction against a supported release. Record:

  • defaults, non-default arguments, environment, and deployment assumptions;
  • what the attacker controls, what the victim does, and what authority the attacker gains;
  • the check or trust boundary allegedly bypassed; and
  • whether the attacker's prerequisites already provide equal or greater authority than the claimed impact.

A non-default configuration may still be vulnerable; a default may intentionally delegate a security decision elsewhere.

Identify the responsible layer

  • FastMCP vulnerability: FastMCP violates a promised boundary in a supported configuration.
  • FastMCP bug: FastMCP behaves incorrectly without creating attacker capability.
  • Upstream vulnerability: The defect belongs to a standard, dependency, identity provider, client, proxy, or platform.
  • Insecure deployment: The operator omits, disables, or delegates a required control without supplying the replacement required by its contract.
  • Expected behavior: The result follows the documented API contract or protocol.
  • Documentation gap: The implementation follows its intended contract, but the guidance creates a reasonable expectation of protection.

Attribute the violated boundary to its owner. Neither a dangerous configuration nor an available external mitigation decides ownership by itself. Distinguish failure of a primary control from failure of defense-in-depth.

Establish FastMCP's contract

Read the code, released documentation, tests, and history. Determine:

  1. What FastMCP promises for the exact configuration, supported API, and affected releases.
  2. Whether the proof of concept bypasses, disables, or delegates that protection.
  3. Whether the behavior follows the implemented protocol despite any stricter FastMCP promise.

If the intended contract remains unclear, ask the subsystem maintainer before accepting the report or proposing a fix. Current code alone does not define supported product behavior.

Show full SKILL.md (238 more words)Show less

Separate OAuth proxy boundaries

For OAuth proxy reports, check each layer independently:

  • Open DCR lets unknown clients register redirects; a matching attacker callback is not a redirect validation bypass.
  • FastMCP consent binds the downstream client; ordinary upstream consent binds FastMCP's shared app.
  • require_authorization_consent=False removes consent; "external" delegates equivalent consent and transaction binding outside FastMCP.
  • PKCE protects the verifier, not a code issued for a malicious client's own challenge.
  • Redirect allowlists are optional policy and can break hosted clients or open DCR.

Review the proposed fix independently

A patch can block the proof of concept and still be wrong. Verify that it:

  • fixes the violated boundary at its source and enforces the claimed property;
  • does not silently change an intentional default or opt-in contract; and
  • preserves supported workflows without assuming one replacement control is the only valid design.

Treat a change to the supported product contract as an enhancement requiring maintainer agreement, independently of the security report.

Classification checkpoint

Before any GitHub mutation, state the decisive configuration and affected versions, boundary owner, realistic impact, and one disposition:

  • accept a draft advisory and prepare a private patch;
  • request specific missing evidence;
  • route as a normal FastMCP bug or upstream issue;
  • close as expected behavior or an insecure deployment;
  • ask the relevant maintainer to decide the contract.

Separately recommend any documentation or warning clarification warranted by the investigation.

When rejecting a report, acknowledge any valid reproduction and explain the decisive precondition.

© PrefectHQ, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/review-security-report of PrefectHQ/fastmcp.

Open the folder on GitHubat commit e2fcc41

Compare with similar skills

Review Security Report next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Security Report compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Security Report this skillPrefectHQ/fastmcp28k—~1.2kAutomated safety check: PassApache-2.0
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Xquik MCPXquik-dev/x-twitter-scraper2111 repos~997Automated safety check: PassMIT
MCP Dart Streamable HTTPleehack/mcp_dart116—~2kAutomated safety check: PassMIT
Building MCP Server On CloudflareCommandCodeAI/agent-skills133—~1.5kAutomated safety check: PassMIT
Nuxt Agent Ready Best Practicesvinayakkulkarni/nxui212—~2.4kAutomated safety check: PassMIT

Similar skills

  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Xquik MCP

    Xquik-dev/x-twitter-scraper

    Connect, verify, and troubleshoot Xquik's remote MCP server.

    211 GitHub starsUsed in 1 repo~997 tokens
    Backend & APIsAuto-check passed
  • MCP Dart Streamable HTTP

    leehack/mcp_dart

    A skill your agent uses when serving an MCP server over HTTP with mcpdart or connecting to a remote one: StreamableMcpServer setup, Host and Origin allowlists (DNS rebinding protection), CORS for…

    116 GitHub stars~2k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Building MCP Server On Cloudflare

    CommandCodeAI/agent-skills

    Builds remote MCP (Model Context Protocol) servers on Cloudflare Workers with tools, OAuth authentication, and production deployment.

    133 GitHub stars~1.5k tokensUpdated 7 mo ago
    Agent WorkflowsAuto-check passed
  • Nuxt agent-readiness guidelines for making a site operable by autonomous AI agents — not just cited by them.

    212 GitHub stars~2.4k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Onboard a new DCR OAuth MCP catalog entry with provider-doc vetting and curl probes.

    40k GitHub stars~1.8k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from PrefectHQ/fastmcp

All 9 skills in this repo
  • Release

    PrefectHQ/fastmcp

    Cut a FastMCP release end to end. An agent skill from PrefectHQ/fastmcp.

    28k GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Docs

    PrefectHQ/fastmcp

    Write or revise a page under docs/ for gofastmcp.com. An agent skill from PrefectHQ/fastmcp.

    28k GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Fastmcp Client CLI

    PrefectHQ/fastmcp

    Query and invoke tools on MCP servers using fastmcp list and fastmcp call.

    28k GitHub stars~823 tokensUpdated yesterday
    Auto-check passed
  • Review Issue

    PrefectHQ/fastmcp

    Review an incoming external issue (and any gated-closed PR behind it) and decide whether to assign the contributor or decline.

    28k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Review PR

    PrefectHQ/fastmcp

    Assess a FastMCP pull request for justified behavior, compatibility, and correctness, then follow CI and review feedback to a revision-specific verdict.

    28k GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Triage

    PrefectHQ/fastmcp

    Find worthwhile FastMCP issues to work on in a backlog or release window, verify promising candidates, and present concrete picks with existing PR links.

    28k GitHub stars~573 tokensUpdated yesterday
    Auto-check passed

Questions about Review Security Report

What does Review Security Report do?

Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them. Review Security Report is an agent skill from PrefectHQ/fastmcp. Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them.

When should I use Review Security Report?

Review Security Report fits situations like: security advisories; bug-bounty submissions; MCP vulnerability claims; proposed security fixes.

How do I install Review Security Report in Claude Code?

Run `npx skills add PrefectHQ/fastmcp --skill review-security-report -a claude-code`. Or copy the skill folder (.agents/skills/review-security-report in PrefectHQ/fastmcp) into .claude/skills/review-security-report in your project. Claude Code loads it when a task matches its description.

How do I install Review Security Report in Codex?

Run `npx skills add PrefectHQ/fastmcp --skill review-security-report -a codex`. Or copy the skill folder (.agents/skills/review-security-report in PrefectHQ/fastmcp) into .agents/skills/review-security-report in your project. Codex loads it when a task matches its description.

Can I use Review Security Report in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PrefectHQ/fastmcp --skill review-security-report -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-security-report, .gemini/skills/review-security-report, .github/skills/review-security-report and .opencode/skills/review-security-report in your project.

What does Review Security Report need to run?

SKILL.md names no scripts, command-line tools or credentials: Review Security Report is instructions for the agent only.

Does Review Security Report access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Review Security Report safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Security Report use?

Review Security Report is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Security Report use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Security Report?

Skills that share tags, products or a category with Review Security Report: MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars), Xquik MCP (Xquik-dev/x-twitter-scraper, 211 stars), MCP Dart Streamable HTTP (leehack/mcp_dart, 116 stars) and Building MCP Server On Cloudflare (CommandCodeAI/agent-skills, 133 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Security Report?

PrefectHQ (a GitHub organization) maintains it in PrefectHQ/fastmcp, which has 28,027 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 10, 2026.

Source: PrefectHQ/fastmcp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.