Mmcp.market

Audit MCP server

by joepangallo·io.github.joepangallo/mcp-audit-server·v3.0.1

Thin MCP and CLI proxy for AI agent and MCP security auditing via a hosted backend

B83/100grade B
What users say
No reviews yet
Be the first
Safety scan
B83/100

full report

Adoption
Growing

0 stars31 downloads/wk

Reviews

Write one

Nobody has reviewed Audit yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Audit tools (10)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • audit_agent_dataflow

    Infer tagged-data exposure and exfiltration paths from MCP config and observed tool capabilities.

  • audit_agent_trust

    Audit an MCP or agent deployment for tool-permission inventory, execution provenance coverage, secret exposure controls, policy drift, and an overall trust score.

  • audit_mcp_config

    Perform static analysis on raw MCP config JSON and identify privilege, auth, transport, and launch risks.

  • audit_mcp_server

    Launch a target MCP server over stdio, enumerate tools, and run active security probes against its exposed tools. Requires AGENT_SECURITY_ADMIN_MODE=1.

  • audit_prompt_injection

    Perform a static prompt-hardening review against a 30+ payload prompt-injection catalog.

  • fix_mcp_config

    Auto-remediate security issues in an MCP config: remove unsafe flags, strip shell wrappers, upgrade transport to TLS, redact inline secrets, add auth placeholders, and constrain filesystem scope.

  • generate_policy

    Generate a JSON security policy from an MCP config that can be enforced by a proxy or middleware.

  • generate_report

    Combine multiple stored audit jobs into a composite report with deduplicated findings and an executive summary.

  • harden_system_prompt

    Analyze a system prompt for injection vulnerabilities and return a hardened version with security guardrails appended.

  • scan_mcp_package

    Scan an npm MCP package for dependency vulnerabilities, dangerous patterns, and permission issues.

Public scan report

scanner v0.1.9 · 2026-09-21 · same rubric, same numbers if you re-run it

no findings
  • Code scan6 source files scanned25/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitystatic API keys via environment variables6/15
  • Maintenancelast push 29 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Overall 83/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Audit in Claude Code, Cursor or VS Code

Runs npx -y ledd-mcp-audit-server on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add mcp-audit-server -- npx -y ledd-mcp-audit-server
Add to Cursor

What the publisher says

From the Audit repository's README, as published. We do not edit it. Read it on GitHub

mcp-audit-server

Thin MCP server and CLI proxy for AI agent and MCP security auditing. It connects to a private audit API to analyze MCP configurations, test prompt injection resistance, trace data flows, scan packages, and generate security policies.

This package is a thin proxy. All scan logic lives in a private backend operated by you or your provider.

Managed hosted flow:

  • set AGENTSECURITYAPI_KEY
  • the package will automatically target https://audit.leddconsulting.com

Self-hosted or private-network flow:

  • set AGENTSECURITYBASE_URL to your HTTPS API origin
  • or set AGENTSECURITYHOST and AGENTSECURITYPORT for a loopback/private deployment

Hosted backend access is not bundled with this package. If you want managed access or a licensed private deployment, contact Ledd Consulting.

Registry and Directories

  • npm package: ledd-mcp-audit-server
  • Official MCP Registry name: io.github.joepangallo/mcp-audit-server
  • Downstream directories such as Glama and PulseMCP should ingest from the official MCP Registry, so you usually do not need separate manual submissions for each site.
  • Glama authorship claim is optional. It only gives you ownership of the Glama page and access to manual sync and re-scan controls.

Install

npm install ledd-mcp-audit-server

Install package: ledd-mcp-audit-server CLI command after install: mcp-audit-server

This is the public package that should be published to npm and listed in public MCP directories. The audit engine itself stays private.

The old package name mcp-server-agent-security is retired. See MIGRATION.md for upgrade steps and the deprecation plan.

Usage as MCP Server

Add to your MCP client configuration (Claude Desktop, Cursor, etc.):

{
  "mcpServers": {
    "mcp-audit-server": {
      "command": "npx",
      "args": ["-y", "ledd-mcp-audit-server", "--mcp"],
      "env": {
        "AGENT_SECURITY_API_KEY": "your-issued-api-key"
      }
    }
  }
}

For a self-hosted backend, add AGENTSECURITYBASE_URL to that same env block.

The server exposes 10 tools over stdio:

Usage as CLI

The CLI forwards commands to the private audit API.

# Hosted quick start
export AGENT_SECURITY_API_KEY=your-issued-api-key

# Audit an MCP configuration file
mcp-audit-server scan-config ./claude_desktop_config.json

# Probe a live MCP server (requires AGENT_SECURITY_ADMIN_MODE=1)
mcp-audit-server scan-server npx -y @modelcontextprotocol/server-filesystem /tmp

# Audit trust posture and policy drift for an agent/MCP deployment
mcp-audit-server scan-trust ./claude_desktop_config.json ./claimed-policy.json

# Scan an npm package for vulnerabilities
mcp-audit-server scan-package @modelcontextprotocol/server-shell

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Audit: common questions

Is Audit MCP server safe?
Mostly: it is graded B (83/100). Read the Audit safety report
How do I install Audit?
It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
Does Audit need an API key?
Yes. The registry entry asks for AGENT_SECURITY_API_KEY.
Is Audit maintained?
The last commit was 35 days ago (2026-08-23). The latest release is v3.0.1.
What can I use instead of Audit?
Servers from other publishers that do the same job: LLM Sandbox MCP server, Butterbase AI MCP server and mcptoon MCP server. Compare all Audit alternatives.

Alternatives to Audit

Same job from other publishers: the closest match first, then the best rated.

All Audit alternatives →
  • LLM Sandbox
    Securely run LLM-generated code in isolated containers across 7 languages and 3 container backends.
    A
  • Butterbase AI
    Butterbase MCP server — manage your backend: schemas, auth, functions, storage, RAG, deploys.
    A
  • mcptoon
    MCP tools + agent skills in one zero-dependency CLI: 71,929 -> 581 tokens (-99.2%, measured).
    A
  • REA
    Reverse engineer anything from your terminal or agent with one CLI and MCP server.
    A
  • llmtrim
    MCP server and proxy that compresses LLM prompts, tool output, and replies to cut token cost.
    A

More from joepangallo →