发现和使用优秀的技能扩展
针对AI代理技能和MCP工具的深度行为安全审计。执行确定性静态分析(AST + Semgrep + 15个专业扫描器)、加密锁文件生成以及可选的LLM驱动意图分析。在安装、审查或批准任何技能、工具、插件或MCP服务器时使用,尤其是在首次使用前。用完整的CWE映射、OWASP标记、行引用安全报告取代基本安全摘要。
Deep behavioral security audit for AI agent skills and MCP tools. Performs deterministic static analysis (AST + Semgrep + 15 specialized scanners), cryptographic lockfile generation, and optional LLM-powered intent analysis. Use when installing, reviewing, or approving any skill, tool, plugin, or MCP server — especially before first use. Replaces basic safety summaries with full CWE-mapped, OWASP-tagged, line-referenced security reports.