Mcp Agent Security Kit

security MCP Server

Practical audit tools and controls for securing MCP servers and agentic AI tool access.

Verified
securitysecurity
4 views1 stars2 forksMIT

Why This Matters

Discovered via github-topic:model-context-protocol and last synced 3mo ago.

Verified
Source
github-topic:model-context-protocol
Stars
1
Last synced
3mo ago
Install
Check source

Install

Install instructions not detected yet

Check the source repository for the latest setup steps.

View source instructions
40
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (40)

MCP-004

Package runner is used without an obvious package version pin

high

MCP-003

MCP-002

Remote MCP server has no clear authentication signal

Severity

Rule

MCP-001

Remote MCP server uses unencrypted HTTP

MCP-010

Filesystem-like tool lacks a read-only signal

MCP-005

Shell or evaluator command can execute arbitrary code

medium

MCP-004

Rule

Risk

MCP-009

Server has no visible owner or risk owner metadata

MCP-006

Dangerous execution flags are present

MCP-014

Credential-like URL userinfo values are configured inline

MCP-022

Browser session or profile data is exposed to the MCP server

MCP-018

Docker-based MCP server image is not pinned to an immutable digest

MCP-026

Kubernetes service account access is exposed to the MCP server

Utility

Purpose

MCP-017

Tool auto-approval is configured with a wildcard

MCP-025

Browser debugging interface is exposed to the MCP server

MCP-033

CI/CD credential context is exposed to the MCP server

MCP-013

Secret-like URL query parameter values are configured inline

MCP-021

Environment file is exposed to the MCP server

MCP-029

Container runtime socket access is exposed to the MCP server

MCP-007

Broad filesystem access is granted

MCP-015

TLS certificate validation is disabled

MCP-023

External-action tools are configured for automatic approval

MCP-031

Database client credential context is exposed to the MCP server

Path

Purpose

MCP-008

Docker configuration uses privileged or host-level access

MCP-016

Docker socket access is exposed to the MCP server

MCP-024

Cloud metadata endpoint or wildcard network scope is reachable by the MCP server

MCP-032

Package registry credential context is exposed to the MCP server

MCP-003

Secret-like values are configured inline in environment variables

MCP-011

Secret-like HTTP header values are configured inline

MCP-019

Authentication scopes or permissions look overbroad

MCP-027

SSH agent socket access is exposed to the MCP server

MCP-012

Secret-like command argument values are configured inline

MCP-020

Credential-bearing local path is exposed to the MCP server

MCP-028

Git credential helper access is exposed to the MCP server

critical

MCP-005

MCP-030

Cloud CLI credential context is exposed to the MCP server