graygnatconsole/mcp-audit-tool

A Python CLI scans Model Context Protocol server configurations for tool poisoning, rug pulls, hardcoded secrets, and command injection risks. The tool generates SARIF reports for CI integration. It targets supply-chain security in AI agent environments, providing a specific audit mechanism for MCP deployments.

Cover image for graygnatconsole/mcp-audit-tool

This Python command-line interface inspects Model Context Protocol server configurations for specific security vulnerabilities. It identifies risks including tool poisoning, rug pulls, hardcoded secrets, and command injection. The system generates SARIF reports, which facilitates integration into continuous integration pipelines. The developer states the tool targets supply-chain security within AI agent environments. Runners execute the script against existing MCP server configuration files. The scan process examines defined parameters to detect potential misconfigurations or malicious entries. Results compile into standard SARIF format for pipeline consumption. Users should verify that target servers remain in development or staging before running automated checks to prevent production noise. Observers should note that the repository currently holds 43 stars and 1 fork on GitHub. This data point suggests early stage adoption rather than established enterprise trust. The project first crossed discovery thresholds today, indicating limited historical uptime or stability records. Users must independently verify scanner accuracy because the author claims detection capabilities without third-party validation metrics.

README

graygnatconsole/mcp-audit-tool View on GitHub

Loading the README from GitHub…