#
ENJA

mighty-security

TryMightyAI/mighty-security

An automated security scanner designed to detect vulnerabilities, command injection risks, and credential leaks in Model Context Protocol (MCP) servers before installation.

98 4MITUpdated 2025-08-19

Overview

mighty-security evaluates remote and local Model Context Protocol (MCP) servers for dangerous code patterns, path traversal flaws, and unauthorized environment variable harvesting. Featuring both a command-line interface and a modern React web dashboard, it incorporates static analysis, taint tracking, and optional LLM-powered deep inspection to protect local machines from malicious agent extensions.

Capabilities

  • Static code analysis for Python, JavaScript, TypeScript, Go, and Rust
  • Detection of command injection, SSRF, path traversal, and credential theft
  • Optional LLM-enhanced threat analysis via Cerebras API
  • Interactive React web dashboard for real-time monitoring and scan management
  • Context-aware profiles (production, development, security-tool)

Best for

Scanning third-party MCP repositories for malicious code or command injection vulnerabilities prior to installation, Integrating into CI/CD pipelines to automatically block insecure agent tools from merging or deploying, Auditing custom-built MCP servers for data exfiltration and credential leaks

Works with

Claude CodeCursorGitHub Copilot
Evoa Score breakdown= Σ (score × weight)
74
Task usefulness20%88 → +17.6

実タスクにどれだけ役立つか(機能の豊富さ・用途の明確さ)。 AIによるcapabilities/use-cases解析

Code quality15%85 → +12.8

実装・指示の品質。 AIによるSKILL.md/README解析

Maintenance15%50 → +7.5

リポジトリがどれだけ活発に保守されているか。 GitHub 最終push日時の新しさ

Documentation12%35 → +4.2

ドキュメントの充実度・分かりやすさ。 README/独自要約の情報量

Security15%100 → +15.0

危険・不審な挙動が無いか。 AIによるセキュリティレビュー

Originality10%90 → +9.0

ありふれたラッパーではない独自性。 AIによる独自性判定

Popularity8%51 → +4.1

コミュニティの採用度。 GitHub Stars/Forks(対数スケール)

Compatibility5%75 → +3.8

対応AIエージェントの広さ。 AIによる対応エージェント判定

Weighted total73.9 / 100

ライセンス不明/制限あり(Red)のSkillは総合スコアに0.85倍の補正を適用します。 ランキングはこのScoreのみで決まり、広告で変わりません。 算出方法の詳細 →

Security considerations

The repository contains safe test malware samples; users should exercise caution and utilize the appropriate profiles when scanning or testing.

Categories

Summary and analysis are original content generated by AI Skills Rank. The skill's source text is not reproduced here — view it on the linked repository.