# Web Audit

> Use this tool when you need to automate web-based security audits for Node.js projects, identifying vulnerabilities and dependencies to streamline security assessment workflows. It solves problems of manual security analysis by providing vulnerability scanning, dependency analysis, and generating markdown reports categorized by severity levels. The tool takes Node.js project package.json files as input and outputs structured, customizable reports, making it ideal for development teams requiring automated vulnerability detection and professional audit documentation.

Canonical page: https://skillsregistry.net/skills/web-audit  
JSON: https://api.skillsregistry.net/v1/skills/web-audit

## Description

MCP server implementation by Shen-zhihao that provides AI assistants with web-based security audit capabilities for Node.js projects, featuring vulnerability scanning, dependency analysis, and markdown report generation. The implementation analyzes both local and remote projects by parsing package.json files, running npm audit commands, and normalizing vulnerability data into structured reports categorized by severity levels (critical, high, moderate, low). Built with EJS templating for customizable report formatting and supporting both current project auditing and remote repository analysis, it streamlines security assessment workflows for development teams who need automated vulnerability detection and professional audit documentation without manual security analysis.

## Trust

- **Trust score (0–1):** 0.82
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-09-28

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/web-audit)
- **Repository:** <https://github.com/shen-zhihao/mcp-web-audit>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "web-audit"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/web-audit` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/web-audit/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
