Adversarial security review for AI skills, repos, MCP servers, and packages before you install them. A read-only scanner plus a five-persona reasoning pass, ending in a GO / GO WITH MITIGATIONS / NO-G
An adversarial security review for any skill, repo, MCP server, or package you're about to trust. It reviews code the way a suspicious security engineer would, then gives you a clear verdict: GO, GO WITH MITIGATIONS, or NO-GO.
Installing an agent skill or an npm package runs someone else's code on your machine, often with access to your files and credentials. Public marketplaces have been seeded with malicious skills that lifted saved logins and wallet files the moment someone installed them. Trust Issues lets you check something before you run it instead of finding out afterward.
You point it at a repo, a skill, an MCP server, or a package, and it does an attacker-minded review and hands you a verdict with the findings behind it.
The review has two layers. First, a read-only scanner does a fast pass over 14 categories of risk, from install hooks and obfuscated payloads to leaked secrets and hidden instructions. Then a five-persona adversarial read looks at what the scanner surfaced and reasons about intent, which is the part a keyword search can't do.
The scanner never runs the code it reviews — it only reads files. It also does no online research: the "search for current attack techniques" step happens in the full workflow, run by the agent or person, not by the shell script. Treat whatever that research pulls in as untrusted evidence, since web pages and repos can themselves carry prompt injection, not as instructions to act on.
From the project README.
Add the radar badge to your README — it shows your project was picked up by MCP Radar and links to this page:
[](https://mcp.liqiwa.com/s/howshannon--trust-issues.html)
Free security & privacy scanner for AI-coded apps. 699 rules, 76 MCP tools, 13-layer defense, zero-trust sandbox, AI firewall. Runs locally, never sends data anywhere. Scan your AI-generated app for l
12122J/mcpvetMCP security scanner — vet a Model Context Protocol server before you add it to Claude Code, Cursor, or Windsurf. Grades it A–F, catching credential theft, tool-poisoning, and install-script payloads
flankerhqd/cyvisguardSecurity control plane for AI agents — identity and delegation, capability policy, data-flow taint and a live audit trail, enforced over MCP. Guards a real Claude Code end to end.
Octolabo/malskannerScan a repo for hidden prompt-injection before your AI agent trusts it — CLI, MCP server & GitHub Action. Run: npx malskanner <repo>. 0 false positives across 5,620 files.
Ed-Marcavage/awesome-security-agent-harnessesAI agents for pentesting, code audit, fuzzing, vulnerability discovery, and reverse engineering — harnesses, sandboxes, security MCP servers, benchmarks, and evals.
0xsline/OpenChatCutLocal-first conversational AI video editor with a professional multi-track timeline, Agent Skills, MCP integration, and Remotion-powered rendering.
The top new MCP servers of the week, every Monday. No spam, unsubscribe anytime.