{"repo":"highflame-ai/ramparts","free":true,"listed":false,"github":"https://github.com/highflame-ai/ramparts","clone":"git clone https://github.com/highflame-ai/ramparts.git","description":"mcp & skill scanner that scans any mcp server or skills for indirect attack vectors and security or configuration vulnerabilities","language":"Rust","stars":96,"topics":["agent","ai","llm","mcp","modelcontextprotocol","security","mcpscan","skills"],"license":"Apache-2.0","category":"mcp-servers","readme_excerpt":"Ramparts: security scanner for MCP servers and AI agent skills A fast, lightweight security scanner for the agent stack — Model Context Protocol (MCP) servers AND AI agent skills (Claude Code commands, agentskills.io bundles, Cursor / Codex / Windsurf / Gemini equivalents) — with built-in vulnerability detection. Overview Ramparts scans the two surfaces an AI agent trusts most: the MCP servers it talks to over the network, and the skill files it loads from disk and executes by name. Both deliver untrusted instructions and tool grants into the agent's loop; ramparts applies the same security pipeline (YARA, LLM analysis, OWASP MCP Top 10 tagging) to both. - MCP scanning covers the Model Context Protocol — the open standard that lets AI assistants connect to databases, file systems, and APIs via tool-calling. Ramparts discovers a server's tools/resources/prompts and audits them for prompt injection, tool poisoning, secret leakage, path traversal, command injection, cross-origin escalation, supply-chain CVEs (via OSV.dev), and more. - Skill scanning covers the markdown/YAML files an agent loads as named capabilities — Claude Code custom slash commands, Cursor / Codex / Windsurf / Gemini equivalents, and first-class support for agentskills.io bundles ( /SKILL.md directories with sibling scripts/ , references/ , assets/ ). Each skill body becomes a synthetic MCP prompt that runs through the same analyzers; bundled scripts get scanned through YARA, name-vs-directory mismatches surf","default_branch":null,"files":null,"tree":[],"storefront":"/r/highflame-ai","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/highflame-ai/ramparts/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}