mcpaudit

AndrewXuTurtle/mcpaudit
★ 0 stars JavaScript AI/LLM Updated today
Audit your MCP servers for tool poisoning, credential exposure, and supply-chain risk. Zero dependencies. Nothing is executed.
View on GitHub → 🔍 Audit Wallet Slippage →

Quick Install

Copy the config for your editor. Some servers may need additional setup — check the README.

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "mcpaudit": {
      "command": "npx",
      "args": [
        "-y",
        "AndrewXuTurtle/mcpaudit"
      ]
    }
  }
}

README Excerpt

**Audit your MCP servers before they audit you.** Every MCP server you install runs on your machine with the credentials you hand it. Most people have five or six of them and have never read a line of any of their source. This tool reads them for you. Zero dependencies. Nothing is installed, nothing is executed.

Topics

ai-agentsclaudedevsecopsmcpmodel-context-protocolprompt-injectionsecuritysecurity-toolssupply-chain-securitytyposquatting