闲社服务运行正常AI智能体自动化平台
m

mcp-tool-security-preflight

Review an MCP tool or Agent Skill before connecting it to real accounts, files, databases, browsers, messaging, payments, or production workflows. Use when the user asks for MCP security review, permission scoping, side-effect controls, failure recovery, or a go-live checklist.

作者:暂未提供 | 来源记录:ClawHub
登记来源
ClawHub
版本
V 1.0.0
检测标记
后台标记通过
999.00 积分
参考价 · 登录确认
0
收藏
来源与检测标记为平台登记信息,并不代表已展示可复核的检测报告。使用前请核对版本、依赖和所需权限,建议先在隔离环境中运行。
概述
安装方式
版本历史

mcp-tool-security-preflight

MCP Tool Security Preflight

Use this skill to produce an evidence-based preflight review for one MCP tool, Agent Skill, or automated workflow integration.

Required Inputs

Ask for or identify:

  • - Tool name, source, maintainer, and version
  • Intended task and users
  • Requested read, write, delete, and admin permissions
  • Data that the tool can receive, store, or transmit
  • Actions that can change external state
  • Timeout, retry, rollback, and credential-revocation behavior

Do not request secrets, passwords, private keys, full customer records, or unredacted production logs.

Review Procedure

  1. 1. Confirm the tool source and version can be identified.
  2. Reduce permissions to the minimum required for the stated task.
  3. Map sensitive data fields and where they may leave the local boundary.
  4. Mark sending, publishing, payment, deletion, and permission changes as external side effects.
  5. Require a clear human confirmation before every high-risk side effect.
  6. Check idempotency, timeout, limited retries, partial-success handling, and rollback.
  7. Test normal, missing, malformed, injection, timeout, repeated-execution, and human-rejection cases.
  8. Return one decision: pass, restricted rollout, or fail.

Use references/mcp-preflight-checklist.md for the full checklist and examples/mcp-tool-risk-register.yaml as the editable risk-register structure.

Output Format

Return:

  1. 1. Scope reviewed
  2. Confirmed evidence
  3. Unverified assumptions
  4. Risk register with severity and owner
  5. Required fixes ordered by priority
  6. Test cases and expected results
  7. Final decision with conditions

Do not claim a control exists unless it is visible in code, configuration, documentation, or a verified runtime test.

下载

v1.0.0 最新 2026-8-17 21:27
初始版本(来自套餐拆分)
返回顶部