agentsclimarketplace

Mcp audit

Skill rohitg00/pro-workflow/skills/mcp-audit

Audit connected MCP servers for token overhead, redundancy, and security. Use when sessions feel slow or before adding new MCPs.From its SKILL.md

Install
npx -y skills add rohitg00/pro-workflow --skill mcp-audit

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.

SKILL.md

2.5 KB, 614 tokens by cl100k_base, as published. Nobody here has run it

MCP Audit

Analyze MCP server overhead and recommend cleanup.

Trigger

Use when:

  • Sessions feel slow or expensive
  • Adding a new MCP server
  • Context fills up quickly
  • Reviewing project configuration

Key Insight

Each MCP server adds ALL its tool descriptions to every API request. A server with 20 tools adds ~2K-4K tokens per request, regardless of whether you use those tools.

Audit Steps

Step 1: List Active Servers

Check all MCP configurations:

cat .claude/settings.json 2>/dev/null | grep -A 50 "mcpServers"
cat ~/.claude/settings.json 2>/dev/null | grep -A 50 "mcpServers"

Step 2: Count Tools Per Server

For each server, estimate token overhead:

  • 1-5 tools: ~200-500 tokens (low overhead)
  • 6-15 tools: ~500-1500 tokens (moderate)
  • 16-30 tools: ~1500-3000 tokens (high)
  • 30+ tools: ~3000+ tokens (excessive — consider tool filtering)

Step 3: Check Usage

Questions to ask:

  • Which servers were actually used this session?
  • Which servers haven't been used in 7+ days?
  • Are there servers with overlapping functionality?
  • Are there servers only needed for specific tasks?

Step 4: Recommend Actions

Disable servers that:

  • Haven't been used in 7+ days
  • Overlap with another active server
  • Are project-specific but you're in a different project

Keep servers that:

  • Are used every session (filesystem, git)
  • Provide unique capabilities needed for current work
  • Have low tool count (<5 tools)

Output

MCP AUDIT
  Active servers: [N]
  Total tools: [N]
  Estimated overhead: ~[N]K tokens per request

  Server Analysis:
    [name] — [N] tools, ~[N] tokens
      Status: KEEP / DISABLE / REVIEW
      Reason: [why]

  Recommendations:
    Disable: [list]
    Keep: [list]
    Review: [list]

  Projected savings: ~[N]K tokens per request (~$X.XX per session)

Thresholds

  • Total servers: <10 (ideal), 10-15 (monitor), >15 (reduce)
  • Total tools: <80 (ideal), 80-120 (monitor), >120 (reduce)
  • Per-server: <15 tools (ok), 15-30 (filter), >30 (split or disable)

Rules

  • Never disable servers without user confirmation
  • Estimate token savings for each recommendation
  • Consider task context — a server might be unused today but critical tomorrow
  • Check for disabledMcpjsonServers to avoid re-recommending already-disabled servers

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Gives 0 of the 12 instructions most audit compliance skills give in 614 tokens

Counted across 960 of the 1,589 authors here whose files we hold, read 2026-09-06

  • Read product marketing context before asking questionsin 29 of 960, across 11 files
  • Rank findings by severityin 29 of 960, across 22 files
  • Generate audit reportin 22 of 960
  • Run the audit scriptin 20 of 960, across 19 files
  • Generate a prioritized action plan reportin 19 of 960, across 11 files
  • Ensure one H1 per pagein 15 of 960, across 5 files
  • Ensure sitemap exists and is accessiblein 14 of 960, across 4 files
  • Verify alt text on all imagesin 12 of 960, across 3 files
  • Determine the audit scope before startingin 12 of 960, across 4 files
  • Verify important pages allowed in robots.txtin 11 of 960, across 2 files
  • Detect business type from homepage signalsin 11 of 960, across 7 files
  • Delegate specialized tasks to subagentsin 11 of 960, across 7 files

Said here and by no other author read

  • List active MCP configurations
  • Count tools per server
  • Estimate token overhead for each server
  • Check server usage history
  • Recommend server actions
  • Estimate token savings for recommendations

Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.