building-an-mcp-server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited building-an-mcp-server (Agent Skill) and scored it 92/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 2 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 2 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP is how an agent gains capabilities it doesn't have natively (a service, a database, an internal API). korgex is MCP-native — it can both consume servers and act as one.
Connecting an existing server (most common)
korgex mcp catalog to see curated presets; korgex mcp add <alias> [--global]to add one. For a custom server: --command <cmd> --args "…" (stdio) or --url <url> --header "Authorization: Bearer ${TOKEN}" (remote).
${VAR} in the config — never inline a token.server__tool.
Authoring a server
model sees), and a JSON-Schema inputSchema. Keep each tool single-purpose.
initialize → tools/list → tools/call overJSON-RPC (stdio or HTTP). Return results as content blocks; surface tool faults as an error result, not a crash.
security-review). Don't expose destructive operations without a guard.
korgex mcp add and confirm tools list + a sample call work.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.