Audit · LangGuard-AI
Author’s activation text, quoted as published
Use this skill ONLY when the user explicitly invokes /scope-mcp:audit (or asks for a "compliance audit"). Runs a compliance audit against the curated action-surface database. Accepts MCP tool ids, API actions, connector wildcards (salesforce.), bare platform names, or a prose description of the agent. Returns a deterministic risk + regulatory exposure report (SOX, GDPR, PCI, HIPAA) with concrete recommendations. Handles both design-time scoping ("should I build this?") and run-time pre-flight ("about to execute these tools — any issues?") — choose the framing in Step 3 based on what the user is actually doing.
Works with: Claude Code (native) · Cursor, Codex CLI (manual)
native: this artifact type is that client's own format
Category: Security — see all ranked ›
Install (Claude Code):
cp -r audit ~/.claude/skills/- Adoption: 5 repos
- Upkeep: 74.0
- Freshness: 83.0
- Evidence coverage: 84% of the inputs this score can use — the rest are unknown, and the score is discounted for it
- Health: active
- Contributors: 2
- License: Apache-2.0
Security audit
Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.
Its own instructions
Its SKILL.md does not say when to use it, show a worked example, cover setup, or state a limitation.
Read from the capability’s own SKILL.md. This is not a grade and does not compare to the instruction-depth verdict on an MCP server — a skill has no tools to document, so that rubric does not apply to it.
You searched for one. Check the rest of your stack:
npx tashan-cli doctorReads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.
Pro adds the history to tashan doctor, so a run over your own config says which of yours gained an advisory, started running an install script, or lost its last maintainer — and what to move to.
- The whole series behind any row, back to the first day we measured it
- The replacement, named — not just the news that something died
tashan doctorover your own config, on your own machine
Start a 7-day trial › Everything measured on this page stays free.
source ↗ · skill:LangGuard-AI/audit
Everything on this page is public evidence and free. What it cannot know is whether you run this — check your whole config, free, in the browser. tashan Pro adds the series behind each row and names a replacement for anything dying.
Already running this? Check your whole config — free, in your browser, nothing installed. Or npx tashan-cli doctor locally, which sends nothing at all.
Measured 2026-09-13 · scorer s5 · how · something wrong here?