More screenshots
Works with the AI tools you already use
ai Security Auditor
Your AI agent has access to 12 tools, reads from a vector database, and executes shell commands.
Free
ai-security-auditor
Example session with this skill installed
"Audit my agent configuration — it uses 5 MCP servers and scrapes web content"
- Read your context and instructions
- Compiled the ai-security-auditor
AI SECURITY AUDIT REPORT
════════════════════════
Agent: content-researcher
Overall Risk: HIGH (2 Critical, 4 High, 3 Medium)
ID Severity Category Finding Remediation
── ──────── ─────────── ──────────────────────────────────────────── ─────────────────────────────────────────
F1 CRITICAL Injection Web scraper output concatenated into context Add content delimiter tokens and strip
unsanitized instruction patterns
F2 CRITICAL Agency Terminal tool has unrestricted shell access Restrict to command allowlist (git, npm,
python)
F3 HIGH Leakage API key hardcoded in system Move to env var
prompt line 23 $AGENT_API_KEY via secret
─────── ──── ─────── ─────────────────────────── ─────────────────────────
manager
F4 HIGH Permissions MCP filesystem server has write access to / Restrict to project directory with path
allowlist
Priority actions: [1] Sanitize web output before context injection
[2] Restrict terminal to allowlist [3] Rotate and remove hardcoded key
Connects securely to your tools. The creator never sees your data.
About this skill
The Problem
Your AI agent has access to 12 tools, reads from a vector database, and executes shell commands. The system prompt was copied from a blog post. A malicious user discovers that crafted input causes the agent to dump environment variables into a public channel. You don't find out days later. Prompt injection is the #1 attack vector against AI agents — and most teams have zero defensive tooling beyond "trust the model."
What You Get
- Scan prompt templates for injection vectors — detect direct concatenation of user input into system prompts, insufficient role separation, XML/markdown tag injection, and recursive override patterns across six attack categories
- Audit tool permission boundaries — map every MCP server and tool integration to a permission matrix (read/write/execute/network) with risk-level classification from LOW to CRITICAL
- Detect data leakage paths — find hardcoded API keys in system prompts, sensitive data persisting in conversation history, context window overexposure, and tool output that returns more data than the agent needs
- Evaluate excessive agency — classify every autonomous action on an escalation ladder (READ_ONLY through FULL_EXECUTE) and flag missing human-in-the-loop gates with blast-radius analysis
- Assess RAG pipeline security — check vector database authentication, document ingestion sanitization, retrieval relevance scoring, and context assembly trust-weighting for poisoned-document attacks
- Generate structured audit findings — CRITICAL/HIGH/MEDIUM/LOW severity with specific line references, OWASP LLM category mapping, and prioritized remediation steps that include before/after code examples
Why This Beats Prompting It Yourself
Asking an agent "is my prompt secure?" returns generic advice about role separation. But it won't trace the full data flow from a tool's untrusted output through your RAG retrieval into the LLM context, identifying that a poisoned document in your vector DB could override system instructions. This skill maps the complete attack surface across six phases with pattern-matching precision — not vibes.
Example Session
You: "Audit my agent configuration — it uses 5 MCP servers and scrapes web content"
Agent:
AI SECURITY AUDIT REPORT
════════════════════════
Agent: content-researcher
Overall Risk: HIGH (2 Critical, 4 High, 3 Medium)
ID Severity Category Finding Remediation
── ──────── ─────────── ──────────────────────────────────────────── ─────────────────────────────────────────
F1 CRITICAL Injection Web scraper output concatenated into context Add content delimiter tokens and strip
unsanitized instruction patterns
F2 CRITICAL Agency Terminal tool has unrestricted shell access Restrict to command allowlist (git, npm,
python)
F3 HIGH Leakage API key hardcoded in system Move to env var
prompt line 23 $AGENT_API_KEY via secret
─────── ──── ─────── ─────────────────────────── ─────────────────────────
manager
F4 HIGH Permissions MCP filesystem server has write access to / Restrict to project directory with path
allowlist
Priority actions: [1] Sanitize web output before context injection
[2] Restrict terminal to allowlist [3] Rotate and remove hardcoded key
Use Cases
- Pre-deployment security review of any AI agent or LLM-powered application
- Evaluating third-party MCP servers before adding them to your agent's toolset
- Post-incident forensics after a suspected injection attack on your agent
- Compliance documentation for regulated industries (finance, healthcare, government)
- Hardening agent configurations during security sprints or red-team exercises
- Training new team members on secure prompt engineering patterns with real examples
Known Limitations
This is static analysis of configuration files — it cannot detect dynamic attacks during live user interaction. Multi-agent trust boundaries and cascading permission escalation are partially covered but require manual review for complex orchestration patterns. Non-English skill files may have undetected issues since patterns are English-focused.
Upgrade to Pro
Free gives the initial snapshot. AI Security Auditor Pro ($5) adds full OWASP LLM Top 10 rules, structured test suites against your tool schemas, compliance exports, and a CI gate that blocks regressions. Upgrade when you operate multiple agents — Pro version.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
19 installs
Downloaded by developers to date
Free forever
No account required to browse
Trust & safety
Security scanned
Verified clean 4 months ago
- Free to download with an account