Home / rohitg00 / pro-workflow · skills/mcp-audit/SKILL.md · GitHub

mcp-audit skillA

mcp-audit is agent-read markdown (skill) from rohitg00/pro-workflow: Audit connected MCP servers for token overhead, redundancy, and security. Use when sessions feel slow or before adding new MCPs..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# MCP Audit

Analyze MCP server overhead and recommend cleanup.

## Trigger

Use when:
- Sessions feel slow or expensive
- Adding a new MCP server
- Context fills up quickly
- Reviewing project configuration

## Key Insight

Each MCP server adds ALL its tool descriptions to every API request. A server with 20 tools adds ~2K-4K tokens per request, regardless of whether you use those tools.

## Audit Steps

### Step 1: List Active Servers

Check all MCP configurations:
```bash
cat .claude/settings.json 2>/dev/null | grep -A 50 "mcpServers"
cat ~/.claude/settings.json 2>/dev/null | grep -A 50 "mcpServers"
```

### Step 2: Count Tools Per Server

For each server, estimate token overhead:
- 1-5 tools: ~200-500 tokens (low overhead)
- 6-15 tools: ~500-1500 tokens (moderate)
- 16-30 tools: ~1500-3000 tokens (high)
- 30+ tools: ~3000+ tokens (excessive — consider tool filtering)

### Step 3: Check Usage

Questions to ask:
- Which servers were actually used this session?
- Which servers haven't been used in 7+ days?
- Are there servers with overlapping functionality?
- Are there servers only needed for specific tasks?

### Step 4: Recommend Actions

**Disable** servers that:
…

Read the whole file at its exact version.

How to install

Latest version
mdr add rohitg00/pro-workflow/mcp-audit@git:20260718.7f7209d
Exact content
mdr add rohitg00/pro-workflow/mcp-audit@sha256:b80e3e219147bbf0

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_f2ulznzhownbwesv.svg)](https://markdownregistry.com/a/art_f2ulznzhownbwesv)

0 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260718.7f7209d latest2026-07-18 7f7209d 2,519 BA view · diff
git:20260331.68dbd4b2026-03-31 68dbd4b 2,498 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (2519 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

rohitg00/pro-workflow · 2,879 stars · license none · pushed 2026-09-24 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_f2ulznzhownbwesv
GET https://markdownregistry.com/api/v1/resolve?ref=rohitg00/pro-workflow/mcp-audit
GET https://markdownregistry.com/api/v1/blob/b80e3e219147bbf02521ecacfed7e940586f6c19af889f52d5515ce6ef0c3fd4

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from rohitg00/pro-workflow

agent-teams skill
rohitg00/pro-workflow · skills/agent-teams/SKILL.md · Coordinate multiple Claude Code sessions as a team — lead + teammates with shared task lists, mailbox messaging, and…
git:20260718.7f7209d · audit A · 2,879 stars
auto-setup skill
rohitg00/pro-workflow · skills/auto-setup/SKILL.md · Auto-configure quality gates, hooks, and settings for a new project. Detects project type and sets up appropriate…
git:20260718.7f7209d · audit A · 2,879 stars
batch-orchestration skill
rohitg00/pro-workflow · skills/batch-orchestration/SKILL.md · Decompose large-scale changes into independent units and spawn parallel agents in isolated worktrees. Use for…
git:20260718.7f7209d · audit A · 2,879 stars
bug-capture skill
rohitg00/pro-workflow · skills/bug-capture/SKILL.md · Capture a user-reported defect as a durable GitHub issue written in the project's own domain language. Explores the…
git:20260417.f9e421e · audit A · 2,879 stars
compact-guard skill
rohitg00/pro-workflow · skills/compact-guard/SKILL.md · Smart context compaction with state preservation. Saves critical files, task progress, and working state before…
git:20260718.7f7209d · audit A · 2,879 stars
context-engineering skill
rohitg00/pro-workflow · skills/context-engineering/SKILL.md · Master the four operations of context engineering — Write, Select, Compress, Isolate. Manage token budgets, compaction…
git:20260718.7f7209d · audit A · 2,879 stars
context-optimizer skill
rohitg00/pro-workflow · skills/context-optimizer/SKILL.md · Optimize token usage and context management. Use when sessions feel slow, context is degraded, or you're running out of…
git:20260718.7f7209d · audit A · 2,879 stars
cost-tracker skill
rohitg00/pro-workflow · skills/cost-tracker/SKILL.md · Track session costs, set budget alerts, and optimize token spend. Use to check costs mid-session or set spending limits.
git:20260718.7f7209d · audit A · 2,879 stars
design-engineering skill
rohitg00/pro-workflow · skills/design-engineering/SKILL.md · Apply interface craft when building or reviewing UI - motion, easing, timing, springs, component feel, and visual…
git:20260718.7f7209d · audit A · 2,879 stars
deslop skill
rohitg00/pro-workflow · skills/deslop/SKILL.md · Remove AI-generated code slop, unnecessary comments, and over-engineering from the current branch diff. Cleans up…
git:20260718.7f7209d · audit A · 2,879 stars
domain-modeling skill
rohitg00/pro-workflow · skills/domain-modeling/SKILL.md · Build the project's shared language and bounded contexts before writing code, so names stay consistent and the agent…
git:20260718.7f7209d · audit A · 2,879 stars
file-watcher skill
rohitg00/pro-workflow · skills/file-watcher/SKILL.md · Configure file watching hooks to auto-react to config changes, env file updates, and dependency modifications. Use to…
git:20260718.7f7209d · audit A · 2,879 stars

Every file in rohitg00/pro-workflow

Other files named mcp-audit

mcp-audit skill
hoangsonww/claude-code-agent-monitor · plugins/ccam-config/skills/mcp-audit/SKILL.md · Audit the configured MCP servers (user + project scope) via the Agent Monitor Config Explorer API: transport (stdio vs…
git:20260804.9eab0d7 · audit A · 1,014 stars
mcp-audit skill
ulises-jeremias/agent-toolkit · plugins/agent-toolkit-complete/.github/skills/mcp-audit/SKILL.md · MCP config + implementation security audit — config secrets/auth, unpinned versions, remote vs local, OAuth, env…
git:20260831.856ee57 · audit B · 18 stars

Browse by kind, by grade A, or by owner.