mcp-audit-tool

🛡️ Security audit CLI for Model Context Protocol (MCP) servers — scan AI agent configs for tool poisoning, rug pulls, hardcoded secrets, command injection & supply-chain risks. Pure Python, SARIF + CI ready.

Stars
139
Last push
2026-09-26
License
MIT
Category
AI & ML

Score breakdown — how scoring works

  • Maintenance

    30 / 30
    • Pushed within 14 days12 days ago+30
  • Adoption

    12.5 / 25
    • GitHub stars (no package published — stars weighted fully)139+12.5
  • Documentation

    25 / 25
    • Comprehensive README (6,000+ chars)10400 chars+10
    • Install / setup instructionsyes+6
    • Tools / capabilities documentedyes+5
    • Code or client-config exampleyes+4
  • Trust signals

    7 / 20
    • OSS license declaredMIT+7
    • First-party vendor implementationno+0
    • DNS-verified registry namespaceno+0
    • Listed in official MCP Registryno+0
    • Owned by an organizationno+0

Install

From sourcegit clone https://github.com/graygnatconsole/mcp-audit-tool

No package published to a registry — see the README for setup instructions.

Always review a server's code and required credentials before connecting it to your MCP client. MCP Vetted scores public metadata — it does not audit code for malicious behavior (yet). Methodology →

View on GitHub ↗