Agent Audit Kit

security MCP Server

Static scanner for MCP-connected AI agent pipelines — 221 rules across 11 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.

Verified
securitysecurity
4 views6 stars0 forksMIT

Why This Matters

Discovered via github-topic:mcp and last synced 3mo ago.

Verified
Source
github-topic:mcp
Stars
6
Last synced
3mo ago
Install
Check source

Install

Install instructions not detected yet

Check the source repository for the latest setup steps.

View source instructions
48
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (48)

console

Output: `console`, `json`, `sarif`

path

`.`

A

90-100

upload-sarif

`true`

high-count

Count of HIGH findings

sarif-file

Path to SARIF output file

Scope

Static scanner + compliance PDFs

Command

Description

0

Scan passed — no findings exceed `--fail-on` threshold

Grade

Score

Supply-Chain

20

14

Invisible Unicode / bidi, skill frontmatter injection, SKILL.md post-install commands, data-exfil primitives, skill name hijacking, cross-tool references, rug-pull (SHA-256 pinning)

4

HTTP endpoints, TLS disabled, deprecated SSE, tokens in URL query strings

9

`@tool` param flows to shell/eval/SQL/SSRF/file/deserialization sinks (Python AST), `load_prompt()` user-path reachability

Flag

Default

1

Scan failed — findings meet or exceed `--fail-on` severity

include-user-config

`false`

12

Missing mutual auth, unbounded delegation, transitive trust, replay protection, schema confusion, HTTP endpoints, JWT lifetime/validation, impersonation

3

Copyleft licenses (AGPL/SSPL), missing licenses, DMCA-flagged packages

all

Comma-separated rule IDs to include

fail-on

`high`

Framework

Coverage

No

No

Category

Rules

low

Minimum severity to report

Input

Default

findings-count

Total number of findings

C

60-74

Yes

No

Proprietary

Proprietary

33

Missing auth middleware (CVE-2026-33032 class), empty IP allowlists, wildcard CORS, path traversal in resource handlers, SSRF (CWE-918), OAuth 2.1 misconfig (PKCE/S256/DPoP), Tasks primitive leakage (SEP-1686), shell injection

7

`enableAllProjectMcpServers`, API URL redirects, wildcard permissions, missing deny rules, missing allowlists

none

Exit 1 at this severity: `critical`, `high`, `medium`, `low`, `none`

critical-count

Count of CRITICAL findings

D

40-59

2

Error — invalid path, malformed config, etc.

Output

Description

B

75-89

License

**MIT**

Language

Scanning Method

Code

Meaning

format

`sarif`

exit-code

0 = pass, 1 = findings exceed threshold

ASI

Title

severity

`low`

F

0-39

stdout

Write output to file

Feature

AgentAuditKit