apisec-inc/mcp-audit

View on GitHub ↗

See what your AI agents can access. Scan MCP configs for exposed secrets, shadow APIs, and AI models. Generate AI-BOMs for compliance.

153 ★43 forksPythonUpdated 3mo ago

What you need to know

Security scanner and CLI (plus web app) that audits AI dev tool configurations (Claude Desktop, Cursor, VS Code) for exposed secrets, API keys, AI models, and risk flags.

Install

pip install mcp-audit, then run mcp-audit scan.

Usage

  • Point it at your MCP configuration files to get a risk report.

Key features

  • detects secrets and API keys in configs
  • identifies AI models and risk flags

Best for

Devs and security teams auditing local AI-tool configuration

Reviewed 2026-08-11

Topics

agent-securityaiai-bomai-securityapi-inventoryappsecclaudecursorcyclonedxdevsecopsllmmcpmodel-context-protocolsbomsecrets-detectionsecuritysupply-chain-security
Stars
153★
Forks
43
Language
Python
License
MIT
Created
2025-12-12
Last push
2026-05-12