MCP Server Security Review
What this skill does
Performs a structured security audit of an MCP server by reviewing its source code for credential handling, data exposure risks, permission scope, transport security, code quality, and documentation. Scores each dimension, checks for common vulnerabilities (hardcoded secrets, eval injection, path traversal), and produces a review report with an approve/conditional/reject recommendation.
Example
MCP server: https://github.com/example-org/slack-mcp-server Transport: stdio Purpose: Allow AI agents to read/post Slack messages and manage channels Intended users: Engineering team (15 developers)
Required Tools
Compatible Agents
Add to your agent
Or install via CLI:
$ npx skills add webrix-ai/agent-skills --skill mcp-server-security-review
Deploy Org-wide
Free for up to 5 users
Related Skills
Abandoned Cart Recovery
Detects abandoned carts and triggers recovery workflows including email sequences, discount offers, and retargeting campaigns. Analyzes cart abandonment patterns to identify friction points in the checkout flow. Tracks recovery rate and revenue recaptured.
A/B Testing
Helps design statistically rigorous A/B tests for marketing campaigns, landing pages, and product features. Calculates required sample sizes, defines success metrics, sets up test variants, and analyzes results with confidence intervals. Prevents common testing mistakes like peeking and underpowered tests.
AI Adoption Dashboard Builder
Creates a multi-tab analytics dashboard for tracking AI tool adoption across your engineering organization. Includes executive KPIs, team-level adoption curves, per-tool usage breakdowns, productivity impact comparisons, and cost tracking. Optionally generates a Grafana dashboard JSON for real-time monitoring.
AI Adoption Readiness Assessment
A structured assessment framework that scores your organization across five critical dimensions of AI readiness. Produces an actionable scorecard with prioritized recommendations, a detailed gap analysis spreadsheet, and optional Jira tickets to track remediation efforts.
Your agents are already in the wild.
Give them a Basecamp. Go from AI chaos to AI work, in minutes.