MCP Audit logo

MCP Audit

Unclaimed

by apisec-inc

See what your AI agents can access. Scan MCP configs for exposed secrets, shadow APIs, and AI models. Generate AI-BOMs for compliance.

Install

$docker run -v $(pwd):/scan mcp-audit scan

Set up this server

This server needs project-specific setup. Follow the project instructions; no reusable public launch command is available yet.

Project instructions
agent-securityaiai-bomai-securityapi-inventoryappsecclaudecursorcyclonedxdevsecopsllmmcpmodel-context-protocolsbomsecrets-detectionsecuritysupply-chain-security

More in Security

Browse the full directory

Unclaimed listing

Is this your MCP server?

This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.

Claim this server

Security profile

Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works

Tool change history

Compared across complete checks of the same configuration. Tools were listed, not invoked. Input-schema changes are not measured here.

No complete tool checks yet.

FAQ

Questions about MCP Audit MCP Server

How do I connect MCP Audit MCP Server to Claude?
The listing records `docker run -v $(pwd):/scan mcp-audit scan` as its setup step. Run it, then follow the repository's instructions for the client configuration; the listing names Claude Desktop, Cursor, Windsurf as compatible clients.
Is MCP Audit MCP Server free?
The listed licence is MIT. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
What can MCP Audit MCP Server do?
MCPVault has not yet recorded the tool list for MCP Audit MCP Server; it is captured when the server passes a live MCP handshake. The description above is what the project publishes.