mcp-audit — security grade SAFE, quality 77/100

Security audit verdict: SAFE · quality 77/100

Flagged: spawns subprocesses. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by apisec-inc · MCP Server · ★ 153

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is mcp-audit safe to install? View the security audit →

About mcp-audit

MCP Audit See what your AI agents can access - before they go live. Web App CLI Quick Start What It Does MCP Audit scans your AI development tools (Claude Desktop, Cursor, VS Code) and reveals: Secrets - Exposed API keys, tokens, database passwords APIs - Every endpoint your AI agents connect to AI Models - Which LLMs are configured (GPT-4, Claude, Llama) Risk Flags - Shell access, filesystem access, unverified sources Source-level Sc

agent-securityaiai-bomai-securityapi-inventoryappsecclaudecursorcyclonedxdevsecops

Quick Facts

Stars153
Forks44
LanguagePython
CategoryMCP Server
LicenseMIT
Quality Score77.3516767754917/100
Open Issues5
Last Updated2026-08-18
Created2025-12-12
Platformsclaude-code, mcp, python
Est. Tokens~16k

mcp-audit alternative? Top 6 similar tools

Looking for a mcp-audit alternative? If you're comparing mcp-audit with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • hol-guard by hashgraph-online · ⭐ 650

    Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, M

  • Wazuh-MCP-Server by gensecaihq · ⭐ 232

    Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability

  • toolhive-studio by stacklok · ⭐ 167

    ToolHive is an application that allows you to install, manage and run MCP servers and connect them to AI agent

  • mcp-observatory by KryptosAI · ⭐ 139

    CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring befo

  • agent-security-scanner-mcp by sinewaveai · ⭐ 121

    Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (

  • youtube-connector-mcp by ShellyDeng08 · ⭐ 71

    MCP server for YouTube — search videos, get transcripts, channels, and playlists. Works with Claude, Cursor &

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is mcp-audit?

mcp-audit is See what your AI agents can access. Scan MCP configs for exposed secrets, shadow APIs, and AI models. Generate AI-BOMs for compliance.. It is categorized as a MCP Server with 153 GitHub stars.

What programming language is mcp-audit written in?

mcp-audit is primarily written in Python. It covers topics such as agent-security, ai, ai-bom.

How do I install or use mcp-audit?

You can find installation instructions and usage details in the mcp-audit GitHub repository at github.com/apisec-inc/mcp-audit. The project has 153 stars and 44 forks, indicating an active community.

What license does mcp-audit use?

mcp-audit is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to mcp-audit?

The top alternatives to mcp-audit on Agent Skills Hub include hol-guard, Wazuh-MCP-Server, toolhive-studio. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools