# Security Audit

> Use this tool when you need to identify and address potential vulnerabilities in Node.js project dependencies. It analyzes package.json dependencies and reports security risks, providing clear insights to inform code safety and compliance decisions. The Security Audit tool offers a command-line interface and supports various output formats, making it easy to integrate into development workflows and CI/CD pipelines.

Canonical page: https://skillsregistry.net/skills/esx-security-audit  
JSON: https://api.skillsregistry.net/v1/skills/esx-security-audit

## Description

This MCP server implementation provides a security audit tool for package.json dependencies. Developed by esx, it leverages npm-audit-report and npm-registry-fetch to analyze and report potential vulnerabilities in Node.js projects. The server is built using TypeScript and integrates with the Model Context Protocol SDK. It offers a command-line interface for easy integration into development workflows and CI/CD pipelines. The implementation focuses on providing clear, actionable security insights, making it particularly useful for development teams prioritizing code safety and compliance. It supports various output formats and can be easily incorporated into existing project management tools and security protocols.

## Trust

- **Trust score (0–1):** 0.94
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** devops-ci
- **Updated:** 2026-09-28

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/esx-security-audit)
- **Repository:** <https://github.com/qianniuspace/mcp-security-audit>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "esx-security-audit"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/esx-security-audit` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/esx-security-audit/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
