Agent skill

MCP Server Security

by sickn33 in sickn33/agentic-awesome-skills

Secure Model Context Protocol (MCP) servers with transport encryption, tool authorization, input validation, and audit logging for safe AI agent integrations.

MITAuto-check passedAgent Workflows

Install MCP Server Security

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill mcp-server-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills mcp-server-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mcp-server-security .claude/skills/mcp-server-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mcp-server-security
GitHub stars
47k
Used in
2 other repos
Token cost
~2.9k tokens
SKILL.md length
515 words
Files
2 (incl. references)
Skills in repo
1,354
Repo updated
First seen
Licence
MIT

At a glance

Secure Model Context Protocol (MCP) servers with transport encryption, tool authorization, input validation, and audit logging for safe AI agent integrations.

  • Works in 4 steps: MCP Threat Model → Transport Security → Authentication and Authorization → …
  • Tasks that involve MCP servers
  • SKILL.md covers 2. MCP Threat Model, 3. Transport Security, 4. Authentication and… and 5. Tool Authorization, plus 3 more sections
  • Calls openssl; needs OAUTH_PUBLIC_KEY

What it does

MCP Server Security is an agent skill from sickn33/agentic-awesome-skills. Secure Model Context Protocol (MCP) servers with transport encryption, tool authorization, input validation, and audit logging for safe AI agent integrations.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/details.md`). Compatibility notes: Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not…

It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve MCP servers

Example prompts

  • “/mcp-server-security”

Requirements

  • A credential in OAUTH_PUBLIC_KEY
  • Compatibility (from SKILL.md): Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. MCP Threat Model
  2. Transport Security
  3. Authentication and Authorization
  4. Tool Authorization

What it can do on your machine

Read from SKILL.md and the folder at commit ec02547. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OAUTH_PUBLIC_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

MCP Server Security loads about 2.9k tokens when it runs, and up to ~8k if it reads all its reference files. Until then it costs about 45 tokens; SKILL.md has 515 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit ec02547, republished under its MIT licence (© sickn33). 515 words, ~2,911 tokens.

Download SKILL.mdSave it as .claude/skills/mcp-server-security/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
mcp-server-security
description
Secure Model Context Protocol (MCP) servers with transport encryption, tool authorization, input validation, and audit logging for safe AI agent integrations.
compatibility
Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.
category
security
risk
safe
source
https://github.com/BagelHole/DevOps-Security-Agent-Skills
source_repo
BagelHole/DevOps-Security-Agent-Skills
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/BagelHole/DevOps-Security-Agent-Skills/blob/main/LICENSE
metadata.author
devops-skills
metadata.version
1.0

MCP Server Security

Comprehensive hardening guide for Model Context Protocol (MCP) servers. MCP is the open standard for connecting AI agents to external tools, data sources, and services. Because MCP servers execute real actions on real infrastructure, they are a high-value attack surface. This skill covers every layer of defense you need before exposing an MCP server to agents in production.


2. MCP Threat Model

Before hardening, understand what you are defending against.

ThreatVectorImpact
Unauthorized tool accessAgent calls tools the user should not have access toPrivilege escalation, data breach
Prompt injection via resourcesMalicious content in MCP resources influences agent behaviorArbitrary tool execution
Data exfiltration via resultsTool results leak sensitive data back to an untrusted agentData loss, compliance violation
SSRF via MCP toolsAgent tricks a tool into making internal network requestsInternal service compromise
Credential theftAPI keys or tokens stored insecurely on the MCP serverFull account takeover
Denial of serviceAgent floods server with tool calls or huge payloadsService unavailability
Man-in-the-middleUnencrypted transport between agent and MCP serverEavesdropping, request tampering
Supply chain compromiseMalicious MCP server package or pluginArbitrary code execution

3. Transport Security

3.1 TLS for Streamable HTTP and SSE Transports

Every MCP server exposed over HTTP must terminate TLS. Never run plain HTTP in production.

Nginx reverse proxy with TLS termination for an MCP server:

nginx
# /etc/nginx/sites-enabled/mcp-server.conf
server {
    listen 443 ssl http2;
    server_name mcp.internal.example.com;

    ssl_certificate     /etc/ssl/certs/mcp-server.crt;
    ssl_certificate_key /etc/ssl/private/mcp-server.key;
    ssl_protocols       TLSv1.3;
    ssl_ciphers         TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256;
    ssl_prefer_server_ciphers on;
    ssl_session_timeout 1d;
    ssl_session_tickets off;

    # HSTS header
    add_header Strict-Transport-Security "max-age=63072000; includeSubDomains" always;

    location / {
        proxy_pass http://127.0.0.1:3001;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Proto $scheme;

        # SSE-specific: disable buffering so events stream immediately
        proxy_buffering off;
        proxy_cache off;
        proxy_read_timeout 86400s;
    }
}
3.2 mTLS Between Agent and Server

For high-security environments, require the agent (client) to present a certificate.

nginx
# Add to the server block above
ssl_client_certificate /etc/ssl/certs/agent-ca.crt;
ssl_verify_client on;
ssl_verify_depth 2;

Generate a client certificate for an agent:

bash
# Create CA (one-time)
openssl req -x509 -newkey ec -pkeyopt ec_paramgen_curve:P-256 \
  -days 365 -noenc -keyout ca-key.pem -out ca-cert.pem \
  -subj "/CN=MCP Agent CA"

# Create agent client cert signed by the CA
openssl req -newkey ec -pkeyopt ec_paramgen_curve:P-256 \
  -noenc -keyout agent-key.pem -out agent-csr.pem \
  -subj "/CN=agent-orchestrator-01"

openssl x509 -req -in agent-csr.pem -CA ca-cert.pem -CAkey ca-key.pem \
  -CAcreateserial -out agent-cert.pem -days 90
3.3 Securing stdio Transport

For local stdio-based servers, the attack surface is the process boundary itself:

jsonc
// claude_desktop_config.json - restrict stdio server permissions
{
  "mcpServers": {
    "filesystem": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-filesystem", "/home/user/safe-dir"],
      "env": {
        "NODE_OPTIONS": "--experimental-permission --allow-fs-read=/home/user/safe-dir --allow-fs-write=/home/user/safe-dir"
      }
    }
  }
}

4. Authentication and Authorization

4.1 OAuth 2.1 Integration

MCP's Streamable HTTP transport supports OAuth 2.1 for client authentication. Configure your server to validate bearer tokens on every request.

typescript
// src/auth.ts - OAuth 2.1 token validation middleware for an MCP server
import { createServer } from "@modelcontextprotocol/sdk/server/index.js";
import { StreamableHTTPServerTransport } from "@modelcontextprotocol/sdk/server/streamableHttp.js";
import express from "express";
import jwt from "jsonwebtoken";

const app = express();

// OAuth 2.1 token validation middleware
function validateBearerToken(req: express.Request, res: express.Response, next: express.NextFunction) {
  const authHeader = req.headers.authorization;
  if (!authHeader?.startsWith("Bearer ")) {
    return res.status(401).json({ error: "missing_token" });
  }

  const token = authHeader.slice(7);
  try {
    const payload = jwt.verify(token, process.env.OAUTH_PUBLIC_KEY!, {
      algorithms: ["RS256"],
      issuer: "https://auth.example.com",
      audience: "mcp-server",
    });
    // Attach scopes for downstream authorization
    (req as any).tokenScopes = (payload as any).scope?.split(" ") || [];
    (req as any).userId = (payload as any).sub;
    next();
  } catch {
    return res.status(403).json({ error: "invalid_token" });
  }
}

app.use("/mcp", validateBearerToken);
4.2 API Key Management

For simpler deployments, use hashed API keys stored server-side:

typescript
// src/apikeys.ts
import { createHash, timingSafeEqual } from "crypto";

interface ApiKeyRecord {
  hashedKey: string;
  userId: string;
  allowedTools: string[];
  rateLimit: number;        // requests per minute
  expiresAt: Date;
}

// Store hashed keys, never plaintext
const apiKeyStore: Map<string, ApiKeyRecord> = new Map();

export function registerApiKey(plainKey: string, record: Omit<ApiKeyRecord, "hashedKey">) {
  const hashed = createHash("sha256").update(plainKey).digest("hex");
  apiKeyStore.set(hashed, { ...record, hashedKey: hashed });
}

export function validateApiKey(plainKey: string): ApiKeyRecord | null {
  const hashed = createHash("sha256").update(plainKey).digest("hex");
  const record = apiKeyStore.get(hashed);
  if (!record) return null;
  if (new Date() > record.expiresAt) {
    apiKeyStore.delete(hashed);
    return null;
  }
  return record;
}

Show full SKILL.md (204 more words)Show less

5. Tool Authorization

5.1 Allowlist Patterns

Never expose every tool to every user. Define an explicit allowlist:

yaml
# config/tool-policy.yaml
policies:
  - role: developer
    allowed_tools:
      - "read_file"
      - "search_code"
      - "run_tests"
    denied_tools:
      - "execute_command"
      - "write_file"
      - "delete_file"

  - role: admin
    allowed_tools: ["*"]
    denied_tools: []

  - role: readonly-agent
    allowed_tools:
      - "read_file"
      - "list_directory"
      - "query_database:SELECT"
    denied_tools: ["*"]

dangerous_tools:
  - name: "execute_command"
    risk: critical
    requires_approval: true
    max_executions_per_session: 5
  - name: "write_file"
    risk: high
    requires_approval: true
  - name: "query_database"
    risk: medium
    allowed_operations: ["SELECT"]
5.2 Per-User Tool Access Enforcement
typescript
// src/toolAuth.ts
import { readFileSync } from "fs";
import { parse } from "yaml";

interface ToolPolicy {
  role: string;
  allowed_tools: string[];
  denied_tools: string[];
}

const config = parse(readFileSync("config/tool-policy.yaml", "utf-8"));
const policies: ToolPolicy[] = config.policies;

export function isToolAllowed(userRole: string, toolName: string): boolean {
  const policy = policies.find((p) => p.role === userRole);
  if (!policy) return false;

  // Explicit deny takes precedence
  if (policy.denied_tools.includes(toolName)) return false;
  if (policy.denied_tools.includes("*") && !policy.allowed_tools.includes(toolName)) return false;

  // Check allow
  if (policy.allowed_tools.includes("*")) return true;
  if (policy.allowed_tools.includes(toolName)) return true;

  return false;
}

// MCP server integration: wrap the tool handler
export function authorizedToolHandler(server: any) {
  const originalCallTool = server.callTool.bind(server);

  server.callTool = async (request: any, context: any) => {
    const userRole = context.session?.userRole || "readonly-agent";
    const toolName = request.params.name;

    if (!isToolAllowed(userRole, toolName)) {
      return {
        content: [{ type: "text", text: `Access denied: tool "${toolName}" is not permitted for role "${userRole}".` }],
        isError: true,
      };
    }
    return originalCallTool(request, context);
  };
}

Contents

When to Use This Skill

Apply this skill whenever you are:

  • Deploying an MCP server that exposes tools (filesystem, database, API) to AI agents.
  • Connecting an agent runtime (Claude Desktop, Cursor, a custom orchestrator) to one or more MCP servers over stdio, SSE, or Streamable HTTP transport.
  • Building a multi-tenant platform where multiple users share the same MCP server.
  • Passing sensitive data (PII, credentials, internal documents) through MCP resources.
  • Operating in a regulated environment (SOC 2, HIPAA, PCI-DSS) where tool invocations must be auditable.

If your MCP server only runs locally over stdio for a single developer with no network exposure, you can relax some transport-layer controls -- but input validation and audit logging still apply.


Limitations

  • Apply guidance only within authorized scope; test destructive steps in non-production first.
  • Docs-only import: upstream scripts and templates not bundled.
Example
bash
# Read-only first: inventory before any active step.
which <tool> && <tool> --help | head -n 20

Adapted from BagelHole/DevOps-Security-Agent-Skills (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: helper scripts and templates not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/mcp-server-security of sickn33/agentic-awesome-skills.

  • SKILL.md
  • references/details.md

Open the folder on GitHubat commit ec02547

Used in 2 other repositories

We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

MCP Server Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

MCP Server Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
MCP Server Security this skillsickn33/agentic-awesome-skills47k2 repos~2.9kAutomated safety check: PassMIT
MCP Server Builderanthropics/skills180k64 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Fastmcp Client CLIPrefectHQ/fastmcp28k1 repos~823Automated safety check: PassApache-2.0
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 64 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Fastmcp Client CLI

    PrefectHQ/fastmcp

    Query and invoke tools on MCP servers using fastmcp list and fastmcp call.

    28k GitHub starsUsed in 1 repo~823 tokens
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Context Mode Output Sandbox

    mksglu/context-mode

    Routes large command, file, API and browser output through context-mode tools so only the needed result enters the agent's context, instead of dumping it via Bash.

    26k GitHub stars~4.1k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,354 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed
  • Content Creator

    sickn33/agentic-awesome-skills

    Drafts and reviews audience-specific content from supplied brand examples, with local scripts for brand voice and SEO diagnostics, channel templates and a content calendar.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed

Categories

Questions about MCP Server Security

What does MCP Server Security do?

Secure Model Context Protocol (MCP) servers with transport encryption, tool authorization, input validation, and audit logging for safe AI agent integrations. MCP Server Security is an agent skill from sickn33/agentic-awesome-skills. Secure Model Context Protocol (MCP) servers with transport encryption, tool authorization, input validation, and audit logging for safe AI agent integrations.

When should I use MCP Server Security?

MCP Server Security fits situations like: tasks that involve MCP servers.

How do I install MCP Server Security in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill mcp-server-security -a claude-code`. Or copy the skill folder (skills/mcp-server-security in sickn33/agentic-awesome-skills) into .claude/skills/mcp-server-security in your project. Claude Code loads it when a task matches its description.

How do I install MCP Server Security in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill mcp-server-security -a codex`. Or copy the skill folder (skills/mcp-server-security in sickn33/agentic-awesome-skills) into .agents/skills/mcp-server-security in your project. Codex loads it when a task matches its description.

Can I use MCP Server Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill mcp-server-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mcp-server-security, .gemini/skills/mcp-server-security, .github/skills/mcp-server-security and .opencode/skills/mcp-server-security in your project.

What does MCP Server Security need to run?

Going by SKILL.md and its folder, MCP Server Security needs the command-line tools its instructions call (openssl) and credentials named OAUTH_PUBLIC_KEY. Our summary lists: A credential in OAUTH_PUBLIC_KEY. Compatibility (from SKILL.md): Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled..

Does MCP Server Security access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is MCP Server Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does MCP Server Security use?

MCP Server Security is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does MCP Server Security use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.1k tokens, read only when the agent opens those files.

What are the alternatives to MCP Server Security?

Skills that share tags, products or a category with MCP Server Security: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Fastmcp Client CLI (PrefectHQ/fastmcp, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains MCP Server Security?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,343 GitHub stars. The repository holds 1,354 skills in this directory. The repository was last updated on October 7, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.