Complete AI Training

MCP server · Security

SkillGuard MCP server

by epistemedeus

Lets your AI check a skill, plugin or MCP server for malware before you install it.

Flow diagram: you ask your AI “Is this skill safe to install?”, on your own computer the SkillGuard MCP server works with skill or plugin, and you get back clean, suspicious or dangerous.

SkillGuard is a free safety checker for Claude Code skills, plugins and MCP servers. It reads the files in a package and warns you if it spots sneaky code, like something that would send your passwords or keys to a stranger. It is handy for anyone who installs add-ons made by people they do not know.

What is an MCP server? The 30-second version

On its own, your AI can only chat with you. An MCP server is a small helper program that gives your AI one extra skill. This helper gives your AI the ability to inspect a skill or plugin and report back whether it looks safe. So when you are about to install something from GitHub, you can ask your AI to check it first.

What this MCP server does

You point your AI at a skill, plugin or MCP server, either as a web link or a folder on your computer. Your AI passes that to SkillGuard, which downloads or opens the files and reads them without running anything. SkillGuard looks for known bad patterns, like secret-stealing code, hidden install scripts, or text that tries to trick your AI. It then hands back a short report with a verdict: clean, suspicious, or dangerous.

Flow diagram: you ask your AI “Is this skill safe to install?”, on your own computer the SkillGuard MCP server works with skill or plugin, and you get back clean, suspicious or dangerous. Click to zoom

What you can do with it

  • Check a GitHub skill or plugin before you install it
  • Scan a folder on your computer for risky code
  • Spot text that tries to trick your AI into ignoring your instructions
  • Find hidden install scripts that would run code on your machine
  • See if a package tries to send your passwords or keys somewhere
  • Get a clear verdict so you know whether to trust a package

Try asking your AI

  • “Scan this skill before I install it: https://github.com/someone/cool-skill”
  • “Is the plugin in my Downloads folder safe to use?”
  • “Check this MCP server for anything that looks like malware”
  • “Does this skill try to read my API keys or send data anywhere?”

What it gives back to you

You get a short report in the chat. It lists the files it looked at and any problems it found, grouped by how serious they are. Each problem comes with a short label, like secret-stealing code or hidden install script. At the end you get a simple verdict: clean, suspicious, or dangerous.

Before you start

What you need

  • Node.js installed on your computer (the free tool that runs npx)
  • The Claude desktop app or another app that supports MCP servers

Good to know

SkillGuard only spots known bad patterns, so a clever new attack could slip past it; treat a clean result as a helpful sign, not a guarantee.

Install it with your AI

Add SkillGuard MCP server to your AI, no technical skills needed

You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.

Sign in to get the install prompt

Members get a ready-made prompt that lets the Claude desktop app check SkillGuard MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.

Sign in Become a member

Who it's for

Anyone who installs Claude Code skills, plugins or MCP servers made by other people, especially if you are not sure how to read the code yourself.