#
ENJA

ramparts

MCP Server

highflame-ai/ramparts

Ramparts is a security scanner designed to audit Model Context Protocol (MCP) servers and AI agent skills for vulnerabilities, prompt injections, and malicious configurations.

96 19Apache-2.0Updated 2026-08-07

Overview

Ramparts provides deep static, heuristic, and LLM-powered security analysis for the emerging AI agent stack. It scans both network-connected MCP servers and local agent skill bundles (such as Claude Code commands and agentskills.io formats) to detect prompt injection, secret leaks, tool poisoning, supply chain CVEs, and structural security threats. Findings are mapped to the OWASP MCP Top 10 and can be exported as SARIF reports for CI/CD pipeline integration.

Capabilities

  • MCP server discovery and multi-transport analysis
  • AI agent skill bundle and flat-file security scanning
  • YARA-based static analysis for malware IOCs and suspicious scripts
  • LLM-powered semantic vulnerability analysis
  • Supply-chain CVE checking via OSV.dev
  • OWASP MCP Top 10 vulnerability tagging
  • SARIF 2.1.0 and detailed markdown report generation

Best for

Conducting security audits on third-party or local MCP servers before deployment, Validating AI agent skill bundles and custom slash commands against safety and spec rules, Integrating security gates into CI/CD pipelines using SARIF report generation, Scanning local IDE configurations for vulnerable or misconfigured agent tooling

Works with

Claude CodeCursorCodex
Evoa Score breakdown= Σ (score × weight)
85
Task usefulness20%100 → +20.0

実タスクにどれだけ役立つか(機能の豊富さ・用途の明確さ)。 AIによるcapabilities/use-cases解析

Code quality15%90 → +13.5

実装・指示の品質。 AIによるSKILL.md/README解析

Maintenance15%100 → +15.0

リポジトリがどれだけ活発に保守されているか。 GitHub 最終push日時の新しさ

Documentation12%42 → +5.0

ドキュメントの充実度・分かりやすさ。 README/独自要約の情報量

Security15%100 → +15.0

危険・不審な挙動が無いか。 AIによるセキュリティレビュー

Originality10%85 → +8.5

ありふれたラッパーではない独自性。 AIによる独自性判定

Popularity8%53 → +4.2

コミュニティの採用度。 GitHub Stars/Forks(対数スケール)

Compatibility5%75 → +3.8

対応AIエージェントの広さ。 AIによる対応エージェント判定

Weighted total85.0 / 100

ライセンス不明/制限あり(Red)のSkillは総合スコアに0.85倍の補正を適用します。 ランキングはこのScoreのみで決まり、広告で変わりません。 算出方法の詳細 →

Security considerations

Ramparts is a defensive security tool designed to detect vulnerabilities, credential leaks, and malicious payloads within AI agent instructions and MCP server endpoints.

Categories

Summary and analysis are original content generated by AI Skills Rank. The skill's source text is not reproduced here — view it on the linked repository.