MCP server · Security
SkillGuard MCP server
by epistemedeus
Lets your AI check a skill, plugin or MCP server for malware before you install it.

SkillGuard is a free safety checker for Claude Code skills, plugins and MCP servers. It reads the files in a package and warns you if it spots sneaky code, like something that would send your passwords or keys to a stranger. It is handy for anyone who installs add-ons made by people they do not know.
What is an MCP server? The 30-second version
On its own, your AI can only chat with you. An MCP server is a small helper program that gives your AI one extra skill. This helper gives your AI the ability to inspect a skill or plugin and report back whether it looks safe. So when you are about to install something from GitHub, you can ask your AI to check it first.
What this MCP server does
You point your AI at a skill, plugin or MCP server, either as a web link or a folder on your computer. Your AI passes that to SkillGuard, which downloads or opens the files and reads them without running anything. SkillGuard looks for known bad patterns, like secret-stealing code, hidden install scripts, or text that tries to trick your AI. It then hands back a short report with a verdict: clean, suspicious, or dangerous.
Click to zoomWhat you can do with it
- Check a GitHub skill or plugin before you install it
- Scan a folder on your computer for risky code
- Spot text that tries to trick your AI into ignoring your instructions
- Find hidden install scripts that would run code on your machine
- See if a package tries to send your passwords or keys somewhere
- Get a clear verdict so you know whether to trust a package
Try asking your AI
- “Scan this skill before I install it: https://github.com/someone/cool-skill”
- “Is the plugin in my Downloads folder safe to use?”
- “Check this MCP server for anything that looks like malware”
- “Does this skill try to read my API keys or send data anywhere?”
What it gives back to you
You get a short report in the chat. It lists the files it looked at and any problems it found, grouped by how serious they are. Each problem comes with a short label, like secret-stealing code or hidden install script. At the end you get a simple verdict: clean, suspicious, or dangerous.
Before you start
What you need
- Node.js installed on your computer (the free tool that runs npx)
- The Claude desktop app or another app that supports MCP servers
Good to know
SkillGuard only spots known bad patterns, so a clever new attack could slip past it; treat a clean result as a helpful sign, not a guarantee.
Install it with your AI
Add SkillGuard MCP server to your AI, no technical skills needed
You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.
Sign in to get the install prompt
Members get a ready-made prompt that lets the Claude desktop app check SkillGuard MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.
Who it's for
Anyone who installs Claude Code skills, plugins or MCP servers made by other people, especially if you are not sure how to read the code yourself.





