mcp-implementation-security-review
github/awesome-copilot
Performs a comprehensive security audit of Model Context Protocol (MCP) implementations, including servers, clients, and tools. This skill reviews code against critical security baselines (MCP-01 to MCP-05), OWASP MCP Top 10, and common Remote Code Execution (RCE) vectors (e.g., command injection, deserialization, SSRF). The output provides a detailed report with file and line references, ensuring compliance and identifying vulnerabilities before release. Use this when auditing network-exposed services or client security posture.