apisec-inc/mcp-audit
View on GitHub ↗See what your AI agents can access. Scan MCP configs for exposed secrets, shadow APIs, and AI models. Generate AI-BOMs for compliance.
153 ★43 forksPythonUpdated 3mo ago
What you need to know
Security scanner and CLI (plus web app) that audits AI dev tool configurations (Claude Desktop, Cursor, VS Code) for exposed secrets, API keys, AI models, and risk flags.
Install
pip install mcp-audit, then run mcp-audit scan.
Usage
- •Point it at your MCP configuration files to get a risk report.
Key features
- ✓detects secrets and API keys in configs
- ✓identifies AI models and risk flags
Best for
Devs and security teams auditing local AI-tool configuration
Reviewed 2026-08-11
Topics
agent-securityaiai-bomai-securityapi-inventoryappsecclaudecursorcyclonedxdevsecopsllmmcpmodel-context-protocolsbomsecrets-detectionsecuritysupply-chain-security
- Stars
- 153★
- Forks
- 43
- Language
- Python
- License
- MIT
- Created
- 2025-12-12
- Last push
- 2026-05-12