Odel
yotta verify mcp

yotta verify mcp

Local
@yottametaPythonMITUpdated Yesterday

Pre-install security scanner for AI agent skills (local stdio MCP). Offline static scan; no upload.

Language: English · 中文

yotta-verify-mcp banner

yotta-verify-mcp · 元信MCP (YuanXin MCP)

YottaMeta's pre-install security scanner for Agent skills, exposed as a stdio MCP server. Before you install any skill, plugin or MCP server, it runs a deterministic static scan — prompt injection, malicious patterns, SKILL.md integrity and permissions — and returns a verdict, an audited badge, a CI gate and a report as MCP tools.

Activates when configuring the 元信 MCP server in an MCP client, wiring a trust-scan into an agent / workflow, or calling the MCP tools.

Zero dependencies (Python 3.8+ standard library); Windows + Linux + macOS; fully local and offline — no network calls, no execution of the scanned code.

License: MIT Standard: agentskills.io npm package GitHub stars last commit PRs welcome

What it is

The skill / plugin market has a trust problem: a 2025 survey of 22,511 skills found 140,963 issues, and 36% contain prompt injection. 元信 MCP gives you a deterministic answer before you install — the same scan as the yotta-verify CLI, exposed as four MCP tools so any MCP client (Claude, VS Code, Codex, Cursor, …) can call it.

It is a pre-install verifier, not a sandbox and not a runtime monitor: it only reads files and prints a report. It never executes the scanned code, never connects to the network for the scan, and never fixes anything.

Why use it

AdvantageDescription
Trust before installA deterministic verdict for any skill / MCP server, instead of "trust me"
Zero dependencyPython 3.8+ standard library; no daemon / database / network
Fully local offlineScans directories and npm tarballs on disk; nothing is executed or uploaded
Drop into any MCP clientStandard stdio MCP server — configure the server, and the four tools appear
Family synergySame rules table as yotta-verify (single source); verdicts merge with yotta-vetter / yotta-security-audit
Free & openMIT; the whole scanner is free

MCP tools

ToolWhat it does
scan_skillPre-install scan: target (dir / .tgz / npm package) → verdict + severity counts + findings
generate_badgeAudited badge: local SVG + shields.io URL; folds in validate / vetter / audit / version / tests
gate_checkCI gate: fail when the worst severity exceeds max_severity (default medium)
get_reportVerification report: Markdown or JSON, same format as the CLI

MCP client configuration

You usually do not need to write the mcpServers entry yourself: after installing this skill, an AI agent auto-adds the yotta-verify-mcp entry per the「AI 自动接入」section in SKILL.md, and falls back to the CLI scanner when MCP tools are unavailable.

Tool reference

scan_skill

Scan a skill directory or package before install.

ParamTypeRequiredMeaning
targetstringyesSkill directory path, .tgz / .tar.gz path, or npm package name (auto npm pack to a temp dir, then scan)

Returns a JSON result: verdict, severity counts, and findings (prompt injection / malicious patterns / SKILL.md integrity).

generate_badge

Generate an audited badge (local SVG + shields.io URL).

ParamTypeMeaning
targetstringOptional: scan this to derive the verdict
verdictstringOptional: set the verdict directly
validatestringOptional: pass / fail (validate-skill result)
vetter / auditstringOptional: external verdicts to fold in
versionstringOptional: version label. Defaults to the scanner (yotta-verify) version (e.g. 0.1.1)
testsintegerOptional: engine test count
outstringOptional: write the SVG to this path

Note: the badge's version segment reflects the version of the scanning engine (yotta-verify), not the MCP package (0.1.4). Pass version to override.

gate_check

CI pre-install gate.

ParamTypeMeaning
targetstringRequired: dir / package to scan
max_severitystringOptional: info / low / medium / high / critical (default medium)

Returns pass, verdict, worst, max_severity and an exit code.

get_report

Generate a verification report.

ParamTypeMeaning
targetstringRequired: dir / package to scan
formatstringOptional: json / markdown (default markdown)
outstringOptional: write the report to this path

Boundary

This is a local, offline, static scan:

  • Directory scan is fully offline — content never leaves your machine.
  • npm package scan only downloads the public package into a temporary directory (then removes it); it does not upload your content and does not execute the scanned package code.
  • It does not perform dynamic analysis, does not fix anything, and does not make the final decision. Treat the verdict as a strong signal and confirm any "install / don't install" decision yourself.
  • Only scan targets you are authorised to evaluate.

Installation of the skill

The package also ships a SKILL.md so an agent can learn how to configure and use the MCP server. Pick any of the four methods below (skill files come from npm; GitHub can be slow without a proxy).

Method 1: npm one-liner (recommended)

# Optional China mirror: npm config set registry https://registry.npmmirror.com
npx -y @yottameta/yotta-verify-mcp --agent <agent-name>      # install to the agent's default user-level skills dir
npx -y @yottameta/yotta-verify-mcp --dir <your-skills-dir>   # point to the skills dir itself (e.g. ~/.codex/skills)
  • --agent <name> installs to that agent's default user-level directory; --list shows each agent's default directory.
  • --dir <path> installs to the given directory.
  • The installer also starts an MCP server when run with no arguments: npx -y @yottameta/yotta-verify-mcp.

Method 2: git clone (developers / git available)

git clone https://github.com/YottaMeta/yotta-verify-mcp.git <your-skills-dir>/yotta-verify-mcp

Method 3: GitHub Download ZIP (manual / no git)

On the GitHub repository YottaMeta/yotta-verify-mcp, click Code → Download ZIP, unzip it and put the yotta-verify-mcp folder into the agent's skills directory.

Method 4: install.sh (multi-agent one-liner script)

bash install.sh --agent <name>   # install to the agent's default user-level directory
bash install.sh --dir <path>     # install to the given directory
bash install.sh --list           # list agents -> default directories

Development & validation

The package ships its own test suite (included in the published package):

# Run the full suite (32 cases) from the skill directory (Python 3.8 / 3.13 both green)
python scripts/test_yotta_verify_mcp.py

# Run the MCP server directly for debugging
python scripts/yotta_verify_mcp.py

References: references/trust-checklist.md (pre-install trust checklist for MCP servers / plugins).

License

MIT © YottaMeta — see LICENSE.