rankgnar/MCP Audit

Security auditor for MCP servers — detect prompt injection, shadow tools, data exfiltration, and supply chain attacks

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathPath to the MCP server to auditno.
severityMinimum severity to report (low, medium, high, critical)nolow
formatOutput format (json, markdown)nomarkdown
outputFile path to save the reportno""
configPath to .mcp-audit.yml config fileno""
no-dynamicSkip dynamic analysisnofalse
no-depsSkip dependency analysisnofalse
fail-onMinimum severity to fail the action (low, medium, high, critical)nohigh
namedescription
totalTotal number of findings
criticalNumber of critical findings
highNumber of high findings
passedWhether the audit passed (no findings >= fail-on severity)