MCP Security Audit
github/awesome-copilot
Audit MCP (Model Context Protocol) server configurations for security issues.
Remediate security vulnerabilities found by Grype or pnpm audit.
$ npx skills add stacklok/toolhive-studio --skill security-vuln-remediation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install stacklok/toolhive-studio security-vuln-remediation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/stacklok/toolhive-studio.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/security-vuln-remediation .claude/skills/security-vuln-remediation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-vuln-remediation" agent skill from https://github.com/stacklok/toolhive-studio/tree/main/.codex/skills/security-vuln-remediation into .claude/skills/security-vuln-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vuln-remediation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/stacklok/toolhive-studio/tree/main/.codex/skills/security-vuln-remediationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add stacklok/toolhive-studio --skill security-vuln-remediation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install stacklok/toolhive-studio security-vuln-remediation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stacklok/toolhive-studio.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/security-vuln-remediation .agents/skills/security-vuln-remediation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-vuln-remediation" agent skill from https://github.com/stacklok/toolhive-studio/tree/main/.codex/skills/security-vuln-remediation into .agents/skills/security-vuln-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vuln-remediation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add stacklok/toolhive-studio --skill security-vuln-remediation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install stacklok/toolhive-studio security-vuln-remediation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stacklok/toolhive-studio.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/security-vuln-remediation .cursor/skills/security-vuln-remediation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-vuln-remediation" agent skill from https://github.com/stacklok/toolhive-studio/tree/main/.codex/skills/security-vuln-remediation into .cursor/skills/security-vuln-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vuln-remediation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/stacklok/toolhive-studio.git --path .codex/skills/security-vuln-remediation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add stacklok/toolhive-studio --skill security-vuln-remediation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install stacklok/toolhive-studio security-vuln-remediation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stacklok/toolhive-studio.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/security-vuln-remediation .gemini/skills/security-vuln-remediation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-vuln-remediation" agent skill from https://github.com/stacklok/toolhive-studio/tree/main/.codex/skills/security-vuln-remediation into .gemini/skills/security-vuln-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vuln-remediation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install stacklok/toolhive-studio security-vuln-remediationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add stacklok/toolhive-studio --skill security-vuln-remediation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/stacklok/toolhive-studio.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/security-vuln-remediation .github/skills/security-vuln-remediation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-vuln-remediation" agent skill from https://github.com/stacklok/toolhive-studio/tree/main/.codex/skills/security-vuln-remediation into .github/skills/security-vuln-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vuln-remediation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add stacklok/toolhive-studio --skill security-vuln-remediation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install stacklok/toolhive-studio security-vuln-remediation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stacklok/toolhive-studio.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/security-vuln-remediation .opencode/skills/security-vuln-remediation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-vuln-remediation" agent skill from https://github.com/stacklok/toolhive-studio/tree/main/.codex/skills/security-vuln-remediation into .opencode/skills/security-vuln-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-vuln-remediation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-vuln-remediationRemediate security vulnerabilities found by Grype or pnpm audit.
Security Vuln Remediation is an agent skill from stacklok/toolhive-studio. Remediate security vulnerabilities found by Grype or pnpm audit. Use when a security scan fails, a CVE needs fixing, or you need to analyze, upgrade, override, or ignore a vulnerable dependency.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Vulnerability scanning, Security review and MCP servers. It works with pnpm, Model Context Protocol and npm. The repository describes itself as: ToolHive is an application that allows you to install, manage and run MCP servers and connect them to AI agents. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 87f7a55. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Vuln Remediation loads about 2.3k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 1,014 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- Do NOT modify `.env` filesAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from stacklok/toolhive-studio at commit 87f7a55, republished under its Apache-2.0 licence (© stacklok). 1,014 words, ~2,338 tokens.
.claude/skills/security-vuln-remediation/SKILL.md (or your agent's skills folder).Playbook for analyzing and remediating security vulnerabilities in this Electron/Node.js project. Applies to both CI (Cursor agent in GitHub Actions) and local development.
pnpm-lock.yaml).grype.yaml (only reports vulnerabilities with a fix available)pnpm audit --prod --audit-level=moderateoverrides block in pnpm-workspace.yaml — used to pin transitive dependencies to patched versions (pnpm 11 no longer reads the pnpm field from package.json)dependencies in package.jsondevDependencies in package.json — not shipped to usersFollow these steps in order. Stop at the first step that resolves the vulnerability.
Run both scanners and capture the output:
grype . --config .grype.yaml
pnpm audit --prod --audit-level=moderateFor each finding, record:
CVE-2024-12345)For each vulnerable package, understand who pulls it in:
pnpm why <package-name>Record:
dependencies (production) or devDependencies (dev-only)Check if a patch/minor upgrade of the direct dependency resolves the CVE:
pnpm update <direct-dependency>Or, if the vulnerable package is a direct dependency itself, update its version range in package.json.
After the change:
pnpm install to regenerate the lockfilegrype . --config .grype.yaml to verify the vulnerability is goneIf the upgrade resolves it, this step is complete. Move to the next vulnerability.
If no non-breaking upgrade is available, or the fix requires a major version bump of a transitive dependency that is safe to force:
Add or update an entry in the overrides block inside pnpm-workspace.yaml. You MUST follow the existing override style used in the project. Current overrides look like this:
overrides:
fast-xml-parser: '>=5.5.9'
lodash-es: '>=4.17.23'
tar: '>=7.5.7'Rules for overrides (follow strictly):
Always use the >= prefix for values — this allows future patches. Example: '>=1.2.3'.
BEFORE writing any override, check pnpm why <package> for multiple major versions. This is mandatory. If the tree contains more than one major line, an unscoped override would force ALL consumers onto the overridden version, breaking packages that expect a different major.
Use a simple top-level override ONLY when one major line exists — if every installation of the package is on the same major, a single package: '>=fixed' entry is safe:
some-package: '>=1.2.3'Use parent-scoped overrides when multiple majors coexist — scope the override to the dependency path that pulls in the vulnerable version using 'parent>package' syntax:
'parent-pkg>vulnerable-pkg': '>=2.0.1'This only overrides vulnerable-pkg when required by parent-pkg, leaving other consumers on their compatible major. Pick the nearest direct parent that exclusively uses the vulnerable major line.
WRONG — never use an unscoped override when multiple majors exist:
vulnerable-pkg: '>=2.0.1'This would force every consumer onto v2, breaking those that depend on v1.
Only override actually vulnerable versions — if pnpm why shows multiple major lines but only one is in the advisory's vulnerable range, override only that version's path. Do not add overrides for versions that are not vulnerable.
Three valid override-key forms — pick the most surgical one that resolves the advisory:
package: '>=fixed' — top-level, only when a single major line exists in the tree (see Rule 3).
'parent>package': '>=fixed' — parent-scoped, when multiple majors coexist and a specific parent pulls in the vulnerable major (see Rule 4).
'package@versionRange': fixedVersion — version-range-keyed, when multiple vulnerable major lines coexist and each needs its own targeted bump regardless of importer. The range lives in the key; the value is a fixed target version (no >= prefix). Example from this repo (pnpm-workspace.yaml):
'brace-expansion@>=4.0.0 <5.0.5': 5.0.5
'brace-expansion@>=2.0.0 <2.0.3': 2.0.3
'brace-expansion@<1.1.13': 1.1.14Prefer this form over many parent-scoped entries when the advisory spans multiple majors. Avoid it when a single-major top-level (form 1) or one parent>package (form 2) would do — those are easier to read.
After the change:
pnpm install to regenerate the lockfilegrype . --config .grype.yaml to verify the vulnerability is goneOnly if ALL of the following are true:
devDependencies tree)Add an ignore entry to .grype.yaml:
ignore:
- vulnerability: CVE-XXXX-XXXXX
package:
name: <package-name>
type: npm
reason: >-
<package-name> is a dev-only dependency (used by <parent-package> for <purpose>).
<CVE-ID> requires <attack-vector> which does not apply to this Electron desktop app.
Fix requires a breaking major upgrade of <parent> that cannot be safely applied.Every ignore MUST include a reason explaining why it is safe to suppress.
For each vulnerability processed, write a summary containing:
| Field | Description |
|---|---|
| CVE ID | The vulnerability identifier |
| Package | Affected package name and version |
| Severity | Critical / High / Medium |
| CVSS Score | Numeric score if available |
| Attack Vector | Network / Local / Adjacent / Physical |
| Production Impact | Yes (in dependencies tree) or No (dev-only) |
| Action Taken | Upgraded / Overridden / Ignored |
| Verification | Whether grype/audit passes after the fix |
When running in plan mode (Phase 1): write all findings and proposed actions to remediation-plan.md in the repository root. Do not modify project files.
When running in implementation mode (Phase 2): read remediation-plan.md, apply the changes to pnpm-workspace.yaml (overrides / audit ignores), package.json (direct dep upgrades), pnpm-lock.yaml, and .grype.yaml as needed, then verify with grype. Update remediation-plan.md with verification results.
Also write a concise pr-body.md for the pull request description using this exact structure:
## Summary
<1-2 sentence description of what was fixed and why>
## Changes
| CVE | Package | Severity | Production | Action | Verified |
| --- | ------- | -------- | ---------- | ------ | --------- |
| ... | ... | ... | Yes/No | ... | Pass/Fail |
## Files Modified
- `pnpm-workspace.yaml`: <what changed, e.g. added override / ignoreGhsas entry>
- `package.json`: <what changed, e.g. bumped direct dep>
- `.grype.yaml`: <what changed, if applicable>
## Verification
- `pnpm audit --prod`: <Pass/Fail>
- `grype . --config .grype.yaml`: <Pass/Fail>Keep the PR body short and scannable. The full analysis stays in remediation-plan.md for reference but is not used in the PR.
Also write a single-line conventional-commit-style title to remediation-title.txt summarizing the specific changes, for example:
fix(security): upgrade tar to 7.5.7, override lodash (CVE-2025-1234, CVE-2025-5678)fix(security): add grype ignore for tmp (dev-only, CVE-2025-9999)fix(security): override fast-xml-parser >=5.5.9 (CVE-2025-4321)Keep it under 72 characters. Mention the key packages and CVEs, not a generic description.
git commands — git operations are handled by the CI workflowgh commands — PR creation is handled by the CI workflow.env filespnpm install after modifying package.json or pnpm-workspace.yaml to regenerate the lockfilegrype . --config .grype.yaml after each remediation to verify© stacklok, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .codex/skills/security-vuln-remediation of stacklok/toolhive-studio.
Open the folder on GitHubat commit 87f7a55
Security Vuln Remediation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Vuln Remediation this skillstacklok/toolhive-studio | 170 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 | |
| MCP Security Auditgithub/awesome-copilot | 40k | — | ~3.1k | Automated safety check: Pass | MIT | |
| Security Reviewbobmatnyc/claude-mpm | 155 | — | ~1.1k | Automated safety check: Pass | Custom licence | |
| ReleaseWebMCP-org/npm-packages | 103 | — | ~1.6k | Automated safety check: Notes | MIT | |
| Node Modules Inspectorantfu/node-modules-inspector | 3k | — | ~2.2k | Automated safety check: Pass | MIT | |
| Golang Pkg Go Devcontext-labs/whip | 1.1k | 2 repos | ~3k | Automated safety check: Pass | MIT |
github/awesome-copilot
Audit MCP (Model Context Protocol) server configurations for security issues.
bobmatnyc/claude-mpm
Security review gate for MCP server installations. An agent skill from bobmatnyc/claude-mpm.
WebMCP-org/npm-packages
Release the @mcp-b monorepo with Changesets and pnpm, using npm trusted publishing in GitHub Actions.
antfu/node-modules-inspector
Inspects a project's installed nodemodules and produces three reports: duplicated packages (installed in multiple versions), packages sorted by install size, and maintenance actions (dep-upgrade…
context-labs/whip
Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
stacklok/toolhive-studio
Deep links in ToolHive Studio. An agent skill from stacklok/toolhive-studio.
stacklok/toolhive-studio
Reproduce and fix bugs using TDD. An agent skill from stacklok/toolhive-studio.
stacklok/toolhive-studio
Spin up and interact with ToolHive Studio's containerized dev environment (Xvfb + noVNC + DinD).
stacklok/toolhive-studio
Create new AI agent skills for Claude Code, Codex, and Cursor.
stacklok/toolhive-studio
Verify API requests in tests. An agent skill from stacklok/toolhive-studio.
stacklok/toolhive-studio
Test that components send correct query parameters or request arguments.
Works with
Categories
Remediate security vulnerabilities found by Grype or pnpm audit. Security Vuln Remediation is an agent skill from stacklok/toolhive-studio. Remediate security vulnerabilities found by Grype or pnpm audit.
Security Vuln Remediation fits situations like: A security scan fails; A CVE needs fixing; you need to analyze; ignore a vulnerable dependency.
Run `npx skills add stacklok/toolhive-studio --skill security-vuln-remediation -a claude-code`. Or copy the skill folder (.codex/skills/security-vuln-remediation in stacklok/toolhive-studio) into .claude/skills/security-vuln-remediation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add stacklok/toolhive-studio --skill security-vuln-remediation -a codex`. Or copy the skill folder (.codex/skills/security-vuln-remediation in stacklok/toolhive-studio) into .agents/skills/security-vuln-remediation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add stacklok/toolhive-studio --skill security-vuln-remediation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-vuln-remediation, .gemini/skills/security-vuln-remediation, .github/skills/security-vuln-remediation and .opencode/skills/security-vuln-remediation in your project.
Going by SKILL.md and its folder, Security Vuln Remediation needs the command-line tools its instructions call (pnpm). Our summary lists: Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Security Vuln Remediation is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Vuln Remediation: MCP Security Audit (github/awesome-copilot, 40k stars), Security Review (bobmatnyc/claude-mpm, 155 stars), Release (WebMCP-org/npm-packages, 103 stars) and Node Modules Inspector (antfu/node-modules-inspector, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
stacklok (a GitHub organization) maintains it in stacklok/toolhive-studio, which has 170 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.
Source: stacklok/toolhive-studio on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.