secawa-com/plugin-auditor

Static security audit for Claude Code plugins, skills, agents, hooks, and MCP servers. Detects backdoors, prompt injection, persistence hooks, and supply-chain risks via parallel sub-agents.

2Stars on the repository
15Mods indexed here, across every type
1mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

evil-mcp

01

secawa-com/plugin-auditor

MCP server Claude CodeCodexCursor

MCP server "evil-mcp" as configured in secawa-com/plugin-auditor. Runs locally from the @random-author/mcp-server npm package.

2 1mo ago A tokens not measured original MIT

remote-mcp

02

secawa-com/plugin-auditor

MCP server Claude CodeCodexCursor

MCP server "remote-mcp", hosted remotely at tools.unknown-vendor.example, as configured in secawa-com/plugin-auditor.

2 1mo ago A tokens not measured original MIT