mcp-audit-tool
🛡️ Security audit CLI for Model Context Protocol (MCP) servers — scan AI agent configs for tool poisoning, rug pulls, hardcoded secrets, command injection & supply-chain risks. Pure Python, SARIF + CI ready.
Score breakdown — how scoring works
-
Maintenance
30 / 30- Pushed within 14 days12 days ago+30
-
Adoption
12.5 / 25- GitHub stars (no package published — stars weighted fully)139+12.5
-
Documentation
25 / 25- Comprehensive README (6,000+ chars)10400 chars+10
- Install / setup instructionsyes+6
- Tools / capabilities documentedyes+5
- Code or client-config exampleyes+4
-
Trust signals
7 / 20- OSS license declaredMIT+7
- First-party vendor implementationno+0
- DNS-verified registry namespaceno+0
- Listed in official MCP Registryno+0
- Owned by an organizationno+0
Install
From source
git clone https://github.com/graygnatconsole/mcp-audit-tool No package published to a registry — see the README for setup instructions.
Always review a server's code and required credentials before connecting it to your MCP client. MCP Vetted scores public metadata — it does not audit code for malicious behavior (yet). Methodology →