Static AST security scanner detecting command injection, leaked secrets, and SSRF in MCP tools.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
A production-ready Model Context Protocol (MCP) Server providing AI coding assistants (Claude Desktop, Cursor, Windsurf, Cline) with native security analysis tools. It enables AI agents to statically audit other MCP servers, tool repositories, and local codebases for critical security vulnerabilities before onboarding or executing them.
This server implements the official Model Context Protocol specification (tools/list and tools/call):
audit_mcp_repositoryPerforms an automated, zero-execution static Abstract Syntax Tree (AST) security audit on a Git repository containing an MCP server implementation.
repository_url (string, required): Public Git URL of the MCP server repository to audit (e.g. https://github.com/example/mcp-server).sub_directory (string, optional): Specific subdirectory within the repository to inspect (useful for monorepos).subprocess.run, child_process.exec, shell invocation in tool execution blocks.os.path.realpath, boundary checks).trust_score (0β100): Weighted security index.grade ("A+", "A", "B", "C", "F"): Security letter grade.findings (array): Line-by-line vulnerability records with CWE identifiers and remediation instructions.markdown_report (string): Pre-formatted human-readable audit report.audit_local_directoryAudits a local filesystem directory containing MCP server source code before deployment.
directory_path (string, required): Absolute or relative filesystem path to the target directory.Add the server to your claude_desktop_config.json:
In Cursor, go to Settings β Features β MCP β Add New MCP Server:
mcp-security-auditorcommandpython3 /absolute/path/to/server.pyRun isolated via Docker using the pre-configured Dockerfile:
Once connected, your AI assistant can execute security pre-flight checks before installing tools:
Unlike runtime scanners that execute arbitrary stdio binaries (creating direct Remote Code Execution risks on the host), this MCP server uses pure static Abstract Syntax Tree (AST) analysis. It inspects Python, TypeScript, and JSON-RPC implementations without ever executing untrusted code.
MIT License β Copyright (c) 2026 Neon Innovation Lab.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/mcp-security-vulnerability-auditor)<a href="https://allmcps.com/mcp/mcp-security-vulnerability-auditor"><img src="https://allmcps.com/api/badge/mcp-security-vulnerability-auditor?style=directory" alt="MCP Security & Vulnerability Auditor on AllMCPs" /></a>