security-scan

Audit tool configurations for security vulnerabilities and injection risks using AgentShield.

1|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/flatrick/mdt --skill security-scan-flatrick
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-scan
Source: https://github.com/flatrick/mdt/tree/main/skills/security-scan
Command: npx skills add https://github.com/flatrick/mdt --skill security-scan-flatrick

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill addresses the critical need to identify and mitigate security vulnerabilities, misconfigurations, and potential injection risks within your tool configurations, ensuring a safer development environment.

Core Features & Use Cases

  • Comprehensive Auditing: Scans instruction files, tool settings, MCP servers, hooks, and agent definitions for security flaws.
  • Vulnerability Detection: Identifies hardcoded secrets, auto-run instructions, prompt injection patterns, overly permissive settings, and supply chain risks.
  • Use Case: Before deploying a new agent or committing configuration changes, run this Skill to proactively catch potential security loopholes, preventing breaches and ensuring compliance.

Quick Start

Run a basic security scan on your current project's tool configuration.

Frequently Asked Questions about security-scan

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan tool configurations for security vulnerabilities and prompt injection risks?

To scan tool configurations for security vulnerabilities, you can use this Skill to audit instruction files, settings, and agent definitions. It detects hardcoded secrets, auto-run instructions, and prompt injection patterns to ensure a safer development environment.

What security misconfigurations can be detected in MCP servers and hooks?

Security misconfigurations detected in MCP servers and hooks include overly permissive settings, auto-run instructions, hardcoded secrets, prompt injection patterns, and supply chain risks. The audit comprehensively evaluates these configurations for potential security loopholes.

Do I need AgentShield installed to audit instruction files and agent definitions?

Yes, you need AgentShield to audit instruction files and agent definitions. The Skill requires AgentShield to be installed on your system or available via npx for execution to perform its comprehensive security scanning operations.

Can I check tool settings for hardcoded secrets before deploying a new agent?

Yes, you can check tool settings for hardcoded secrets before deploying a new agent. Running this Skill proactively catches potential security loopholes in configuration changes, preventing breaches and ensuring compliance.

What's the best way to identify supply chain risks in tool configurations?

The best way to identify supply chain risks in tool configurations is to run a comprehensive audit using this Skill. It leverages AgentShield to scan instruction files and agent definitions, proactively detecting supply chain vulnerabilities before deployment.