A CI-friendly open-source CLI that statically audits MCP servers before they are wired into AI agents. It flags tool poisoning, hidden Unicode payloads, misleading annotations, and lax schemas, without ever invoking a tool, and reports findings by severity for pipeline gating.
MCPpedia last refreshed this data
MCP Server Audit A Static Security And Hygiene Audit CLI For MCP Servers is an MCP server that a CI-friendly open-source CLI that statically audits MCP servers before they are wired into AI agents. It flags tool poisoning, hidden Unicode payloads, misleading annotations, and lax schemas, without ever invoking a tool, and reports findings by severity for pipeline gating. Its tool list has not been published yet over stdio and http, requires no API key, and scores 81/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients - only the file and path differ.
{
"mcpServers": {
"mcp-server-audit-a-static-security-and-hygiene-audit-cli-for-mcp-servers": {
"args": [
"mcp-server-audit"
],
"command": "uvx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Static security and hygiene audit for MCP servers. Point it at any Model Context Protocol server (or an offline dump of its tool definitions) and get a ranked report of tool-poisoning indicators, lax schemas, misleading annotations, and high-impact capabilities. Drop it into CI and block merges on critical findings.
Run this in your terminal to verify the server starts. Then let us know if it worked - your result helps other developers.
uvx 'mcp-server-audit' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories - click any category to see the underlying evidence.
No known CVEs.
Checked mcp-server-audit against OSV.dev.
Click any tool to inspect its schema.
Be the first to review
Have you used this server?
Share your experience - it helps other developers decide.
Sign in to write a review.
Others in ai-ml
2,500+ scientific tools for AI scientists: life science, research, literature, and more.
MCP server for mobile app automation: verify, control, and debug iOS, Android, TV, and desktop apps
Codebase knowledge graph for AI agents — 162 languages, sub-ms queries, 99% fewer tokens.
Read-only access to 71 Suede skills: discovery, install options, SEO audits, A-F grading.
MCP Security Weekly
Get CVE alerts and security updates for MCP Server Audit A Static Security And Hygiene Audit CLI For MCP Servers and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.