rokha-audit
Security and compliance audit for MCP tools, agents, and skills found in the wild. Run before installing or invoking any unfamiliar tool. Produces a clear "safe to use / here's how" or "found these vulnerabilities" verdict with the schema, endpoint, install command, and trust signals the agent or user needs to make a decision. Use when the user mentions auditing, vetting, security-checking, or "is this safe" about an MCP tool, ClawHub skill, or Smithery server.
- Version
- 0.1.0
- License
- MIT
- Compatibility
- Requires Rokha's `rokha_audit` MCP tool (served by rokha-protocols on port 8001 in dev, or Rokha's public MCP endpoint in prod). Stage 2 probe is optional and benefits from a sandboxed Node environment (Rokha's cloud runtime sandbox, Claude Code's bash, or any local Node).
Pinned to revision eece22d85714, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/rokha-audit/SKILL.md
- skills/rokha-audit/references/audit-harness-schema.md
- skills/rokha-audit/references/probe-stdio-mcp.md
Every link opens the file at its source, pinned to the revision this page describes.