# sigil

> sigil — sigildev-sigil. Use this tool when you need to identify security vulnerabilities in your MCP server's static source code, solving problems such as hidden backdoors, insecure coding practices, and potential exploits. It analyzes git-based code repositories, providing outputs that highlight potential security threats. Ideal for use during code reviews, audits, or prior to deployment to ensure secure server setup.

Canonical page: https://skillsregistry.net/skills/sigildev-sigil  
JSON: https://api.skillsregistry.net/v1/skills/sigildev-sigil

## Description

Static source code security analysis for MCP servers

## Trust

- **Trust score (0–1):** 0.65
- **Verification tier:** scanned
- **Last scanned:** 2026-06-18

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **Category:** security
- **Updated:** 2026-09-20

## Source

- **Source listing:** [GitHub](https://github.com/sigildev/sigil)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "sigildev-sigil"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/sigildev-sigil` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/sigildev-sigil/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
