Statically audit an MCP server's blast radius before installation.
Copy the install command and let the AI configure it · recommended for beginners
Please install the "MCP Blast-Radius Auditor" MCP server from askskill: Run: claude mcp add 'io-github-aos-standard-mcp-blast-radius' -- uvx mcp-blast-radius
Please perform a static blast-radius audit on this MCP server and assess the likely permission scope, risk areas, and parts that need closer review before installation. Continue with any visible information even if no manifest is provided.
A pre-install risk audit summarizing potential blast radius, key risks, and review recommendations.
Please run a static blast-radius audit for these two MCP servers and compare which appears riskier before installation, focusing on exposure surface and potential impact scope differences.
A side-by-side comparison to help decide which server to choose or review first.
This MCP server currently has no manifest. Please perform an initial blast-radius audit using available static information and note any uncertainty caused by missing details.
An initial risk assessment under limited information, with clear caveats about confidence and scope.
Developers or DevOps teams can run a static blast-radius audit before installing a new MCP server to understand likely impact scope and security exposure in advance.
When an MCP server does not provide a manifest, teams can still run an initial static audit to decide whether it should move forward to deeper review or installation.
It performs a static blast-radius audit on an MCP server before agent installation. The goal is to assess potential impact scope in advance rather than after deployment.
Not necessarily. The description explicitly says the manifest is optional, so auditing can still be done without one.
Based on the description, it is a static audit tool focused on pre-install blast-radius assessment. For deeper implementation details and comparisons with other tools, see the source repository.
Scan configured MCP servers locally and generate inventory with risk scores.
Audit MCP server vulnerabilities with a local LLM and attack-pattern retrieval.
Scan MCP servers for runtime, static, config, dependency, and compliance risks.
Audit MCP configs for exposed access, secrets, models, and compliance AI-BOMs.
Retrieve and verify audit regulations, clauses, and audit item references.
Review MCP servers for quality, security, scores, and improvement plans.