Audit MCP configs for exposed access, secrets, models, and compliance AI-BOMs.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "mcp-audit" yet — see the docs or source repo.
Scan this MCP configuration directory for exposed API keys, tokens, overly broad permissions, and suspicious external service connections. Rank findings by severity and provide remediation steps.
A risk-ranked audit report listing exposed items, permission issues, affected config files, and remediation advice.
Analyze the current MCP configuration and show which tools, APIs, data sources, and models AI agents can access. Flag unregistered or unknown shadow APIs and output an inventory.
An access inventory covering tools, endpoints, models, permission scopes, and shadow API risk flags.
Generate an AI-BOM from the MCP configuration, summarizing models, vendors, connectors, data access scope, and security controls for compliance review.
A structured AI-BOM document for security audits, vendor management, and internal compliance records.
Scan configured MCP servers locally and generate inventory with risk scores.
Scan MCP tool descriptions for prompt injection and privilege escalation risks.
Scan MCP servers and AI tools for risks with scoring and auto-protection.
Scan MCP server configs for injections, secrets, and dangerous commands.
Continuously scan and monitor MCP operations for agent-tool security risks.
Analyze AI security, scan vulnerabilities, and monitor code leaks efficiently.