apisec-inc/MCP Audit

Scan repository for Model Context Protocol (MCP) configurations

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit May 12, 2026
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: apisec-inc/mcp-audit@e06f35091d4424b973e5e3d36dc01ddcf593bcb7 # v1.0.0

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
pathPath to scan (defaults to repository root)no.
fail_on_riskFail if MCPs with this risk level or higher are found (none, low, medium, high)nonone
policy_filePath to policy file for validationno""
output_formatOutput format (json, markdown, table)nojson
namedescription
total_mcpsTotal number of MCPs found
with_risksNumber of MCPs with risk flags
high_risksNumber of high-risk MCPs
results_filePath to results JSON file