MCP Configuration Security Sentinel
Paste the following prompt into your AI chat to install this skill:
Please install @user_15292d5a/yjkj-mcp-sentinel into your AI assistant according to https://skillhub.cn/install/skillhub.md.
About this skill
Problem to Solve
MCP, Cursor, Claude Desktop, Zed, and VS Code agent configurations are often simple JSON files, but the risk is hidden in command strings and paths. A bash -lc wrapper, an npx launcher, a root filesystem path, or an inline API_KEY=... value can expand local execution, filesystem exposure, or credential leakage. Prompt text can also contain injection-style instructions. MCP Sentinel is a static scanner for these configuration files, giving engineers a focused set of review signals before the config is used.
How the Skill Works
The skill wraps the open-source TypeScript CLI mcp-sentinel and inspects common locations such as .mcp.json, mcp.json, .cursor/mcp.json, .vscode/mcp.json, claude_desktop_config.json, and .zed/settings.json. It reports findings in practical categories: interactive shell launchers, package-runner startup commands, broad filesystem access, secret-looking environment keys or values, destructive startup arguments, pipe-to-shell installers, and suspicious prompt-injection or exfiltration language. A typical workflow is to choose the project root, run the audit, summarize findings by severity, and then explain what each configuration grants, why it is risky, and what a narrower alternative would look like. When fixing, the preferred direction is to scope paths to the smallest useful directory, remove shell wrappers where possible, and replace inline secrets with environment references.
Limitations
MCP Sentinel is a best-effort static scanner, not a complete security review. It is useful for reviewing MCP server configs, AI client configs, or third-party agent settings, but it does not replace dynamic runtime analysis, dependency auditing, or verification of live credentials. Findings should be treated as prompts for human review and remediation, not as proof of compromise.
Use Cases
- Review a shared `.mcp.json` before merge to flag `bash` launchers, broad directories, or inline secrets.
- Inspect a Cursor config to identify `npx` runners, parent-directory paths, and prompt-injection wording.
- Check Claude Desktop config before rollout to ensure env references replace plaintext API keys and broad paths.
- Audit VS Code MCP settings and summarize severity-ranked findings with remediation guidance.
Best For
- Ops engineers onboarding MCP servers need to confirm startup commands and filesystem paths are not over-broad before launch.
- Engineers maintaining Cursor or Claude Desktop configs want to spot inline secrets, shell wrappers, and suspicious prompt text.
- Security engineers reviewing code need to include AI agent config files in static risk checks.
- Platform engineers integrating AI tooling need severity-ranked remediation clues before merging configuration changes.
Related Skills
A lightweight wrapper and automation tool for Jaeger-related GitHub scenarios.
Vault Wrap is a wrapping skill for Vault and GitHub automation.
Port management, threat-intel audits, drift checks, and multi-node monitoring for self-hosted infrastructure.
Provides health checks for HTTP, TCP, Ping, and log sources with dynamic-threshold alerts, anomaly detection, and scheduled inspection reports.