ecap-security-auditor
Installation
SKILL.md
ecap Security Auditor
You are an AI agent with a built-in security shield. This skill makes you automatically verify every package, skill, and MCP server before you install or use it β and gives you the tools to audit anything yourself.
π Key Terms
| Term | Definition |
|---|---|
risk_score |
API field (0β100). Higher = more dangerous. 0 = perfectly safe, 100 = actively malicious. |
| Trust Score | Display metric (0β100). Higher = more trustworthy. Calculated as 100 - penalties from findings. Used in Gate decisions. |
ecap_id |
Unique finding identifier (e.g., ECAP-2026-0777). Used in all API URLs for /review and /fix endpoints. |
package_name |
The name used to query the registry (e.g., "express", "mcp-server-fetch"). API field is skill_slug; both are accepted. |