{"name":"io.github.joepangallo/mcp-audit-server","slug":"joepangallo-mcp-audit-server","title":null,"description":"Thin MCP and CLI proxy for AI agent and MCP security auditing via a hosted backend","url":"https://mcp.market/server/joepangallo-mcp-audit-server","rating":null,"grade":"B","score":83,"certified":false,"status":"active","category":"ai","tags":["ai","security"],"presence":{"score":23,"stars":0,"forks":0,"downloads_week":31,"last_push_at":"2026-08-23T23:59:47.000Z","license":"MIT"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/joepangallo/mcp-audit-server","website":null,"version":"3.0.1","remotes":[],"packages":[{"registryType":"npm","identifier":"ledd-mcp-audit-server","version":"3.0.1","transport":{"type":"stdio"},"environmentVariables":[{"description":"API key for the managed hosted audit backend","isRequired":true,"format":"string","isSecret":true,"name":"AGENT_SECURITY_API_KEY"},{"description":"Optional HTTPS API origin for self-hosted or private deployments","format":"string","name":"AGENT_SECURITY_BASE_URL"}]}],"tools":[{"name":"audit_agent_dataflow","description":"Infer tagged-data exposure and exfiltration paths from MCP config and observed tool capabilities.","write_action":false,"price_micros":0,"input_schema":null},{"name":"audit_agent_trust","description":"Audit an MCP or agent deployment for tool-permission inventory, execution provenance coverage, secret exposure controls, policy drift, and an overall trust score.","write_action":false,"price_micros":0,"input_schema":null},{"name":"audit_mcp_config","description":"Perform static analysis on raw MCP config JSON and identify privilege, auth, transport, and launch risks.","write_action":false,"price_micros":0,"input_schema":null},{"name":"audit_mcp_server","description":"Launch a target MCP server over stdio, enumerate tools, and run active security probes against its exposed tools. Requires AGENT_SECURITY_ADMIN_MODE=1.","write_action":false,"price_micros":0,"input_schema":null},{"name":"audit_prompt_injection","description":"Perform a static prompt-hardening review against a 30+ payload prompt-injection catalog.","write_action":false,"price_micros":0,"input_schema":null},{"name":"fix_mcp_config","description":"Auto-remediate security issues in an MCP config: remove unsafe flags, strip shell wrappers, upgrade transport to TLS, redact inline secrets, add auth placeholders, and constrain filesystem scope.","write_action":false,"price_micros":0,"input_schema":null},{"name":"generate_policy","description":"Generate a JSON security policy from an MCP config that can be enforced by a proxy or middleware.","write_action":false,"price_micros":0,"input_schema":null},{"name":"generate_report","description":"Combine multiple stored audit jobs into a composite report with deduplicated findings and an executive summary.","write_action":false,"price_micros":0,"input_schema":null},{"name":"harden_system_prompt","description":"Analyze a system prompt for injection vulnerabilities and return a hardened version with security guardrails appended.","write_action":false,"price_micros":0,"input_schema":null},{"name":"scan_mcp_package","description":"Scan an npm MCP package for dependency vulnerabilities, dangerous patterns, and permission issues.","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":83,"grade":"B","scanned_at":"2026-09-21T13:07:15.346Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-21T13:07:15.375Z","components":{"code":{"score":25,"max":25,"notes":["6 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":15,"max":15,"notes":["last push 29 days ago"]},"identity":{"score":8,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[],"inputs":{"packages":[{"registryType":"npm","identifier":"ledd-mcp-audit-server","version":"3.0.1","found":true,"license":"MIT","hasInstallScripts":false,"dependencyCount":1,"publishedAt":"2026-08-23T23:39:44.140Z","repositoryUrl":"git+https://github.com/joepangallo/mcp-audit-server.git","weeklyDownloads":31}],"repo":{"found":true,"owner":"joepangallo","repo":"mcp-audit-server","archived":false,"pushedAt":"2026-08-23T23:59:47Z","stars":0,"forks":0,"openIssues":0,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/4562312?v=4","ownerCreatedAt":"2013-05-29T17:42:04Z","license":"MIT"},"icon":{"url":null,"source":"none"},"presence":{"stars":0,"forks":0,"downloadsWeek":31,"license":"MIT","lastPushAt":"2026-08-23T23:59:47.000Z","score":23}}}},"grade_history":[],"reviews":[]}