{"_id":"@dj_abstract/mcp-audit","_rev":"5-0dc3896a884c33d209d8563238f55793","name":"@dj_abstract/mcp-audit","dist-tags":{"latest":"0.4.0"},"versions":{"0.1.0":{"name":"@dj_abstract/mcp-audit","version":"0.1.0","keywords":["mcp","model-context-protocol","security","audit","ai-security","prompt-injection","tool-poisoning","llm-security","agent-security"],"author":{"name":"Arthur Abrego"},"license":"MIT","_id":"@dj_abstract/mcp-audit@0.1.0","maintainers":[{"name":"dj_abstract","email":"abrego.arthur@gmail.com"}],"homepage":"https://github.com/abregoarthur-star/mcp-audit#readme","bugs":{"url":"https://github.com/abregoarthur-star/mcp-audit/issues"},"bin":{"mcp-audit":"bin/mcp-audit.js"},"dist":{"shasum":"50c1a1c3b955b8bd824ab12a8792ffdecfb1f1ec","tarball":"https://registry.npmjs.org/@dj_abstract/mcp-audit/-/mcp-audit-0.1.0.tgz","fileCount":25,"integrity":"sha512-vIRuS/DWfQBwvG7tA7pbw+KWRbG7mduOKQyB8VsM5cKHApENKFXkxbq8Nass9LiyqLKie89WsIy6jGZsKaWvNg==","signatures":[{"sig":"MEYCIQD4jeakTJZQlU+vBklTCeGPqO/1HgN+t1SB+/dS7dws+wIhAI9WffsXR2ZwqegIDbc8mIlP6iBT0WvqIZ9ZHYiGfi4s","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":81054},"main":"src/index.js","type":"module","engines":{"node":">=20"},"exports":{".":"./src/index.js"},"gitHead":"9022c6006f9c2a348f450a1175eb848c5826c447","scripts":{"test":"node --test 'test/**/*.test.js'","start":"node bin/mcp-audit.js","audit:self":"node bin/mcp-audit.js scan --manifest test/fixtures/sample-manifest.json","audit:brain":"node bin/mcp-audit.js scan --stdio 'node ../dj-abstract-ai-brain/src/agents/brain-tools-mcp.js'"},"_npmUser":{"name":"dj_abstract","email":"abrego.arthur@gmail.com"},"repository":{"url":"git+https://github.com/abregoarthur-star/mcp-audit.git","type":"git"},"_npmVersion":"11.6.2","description":"Security auditor for Model Context Protocol (MCP) servers — scans tool definitions for prompt injection, tool poisoning, unsafe combinations, and other AI-native vulnerabilities.","directories":{},"_nodeVersion":"25.2.1","dependencies":{"kleur":"^4.1.5","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-audit_0.1.0_1776484974971_0.7282672173419305","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@dj_abstract/mcp-audit","version":"0.2.0","keywords":["mcp","model-context-protocol","security","audit","ai-security","prompt-injection","tool-poisoning","llm-security","agent-security"],"author":{"name":"Arthur Abrego"},"license":"MIT","_id":"@dj_abstract/mcp-audit@0.2.0","maintainers":[{"name":"dj_abstract","email":"abrego.arthur@gmail.com"}],"homepage":"https://github.com/abregoarthur-star/mcp-audit#readme","bugs":{"url":"https://github.com/abregoarthur-star/mcp-audit/issues"},"bin":{"mcp-audit":"bin/mcp-audit.js"},"dist":{"shasum":"fbaa14c6aea7fb0abb78a7493574bc55a9b6e922","tarball":"https://registry.npmjs.org/@dj_abstract/mcp-audit/-/mcp-audit-0.2.0.tgz","fileCount":25,"integrity":"sha512-qeIlkY5dyihN8RuxDkYrHuMSNtRr+87TZgbPd3JFzoqqcGp6GZx2fO+sU3Djezqo8e+qpVkNmo0105ZSiS/EdQ==","signatures":[{"sig":"MEUCIAR4ZcYgdfPveTJ+JPZZodl0JFna9p5mf/zoEhMYc/nnAiEAgmMIy0Q0vNjlig4Gv1W+VMtQ7vBhl0GUBc4nQmEaDM0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":87844},"main":"src/index.js","type":"module","engines":{"node":">=20"},"exports":{".":"./src/index.js"},"gitHead":"bab5d36da935bf9ccd7048b33de2abc99b3edfba","scripts":{"test":"node --test 'test/**/*.test.js'","start":"node bin/mcp-audit.js","audit:self":"node bin/mcp-audit.js scan --manifest test/fixtures/sample-manifest.json","audit:brain":"node bin/mcp-audit.js scan --stdio 'node ../dj-abstract-ai-brain/src/agents/brain-tools-mcp.js'"},"_npmUser":{"name":"dj_abstract","email":"abrego.arthur@gmail.com"},"repository":{"url":"git+https://github.com/abregoarthur-star/mcp-audit.git","type":"git"},"_npmVersion":"11.6.2","description":"Security auditor for Model Context Protocol (MCP) servers — scans tool definitions for prompt injection, tool poisoning, unsafe combinations, and other AI-native vulnerabilities.","directories":{},"_nodeVersion":"25.2.1","dependencies":{"kleur":"^4.1.5","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-audit_0.2.0_1776491826809_0.8084451268735482","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@dj_abstract/mcp-audit","version":"0.3.0","keywords":["mcp","model-context-protocol","security","audit","ai-security","prompt-injection","tool-poisoning","llm-security","agent-security"],"author":{"name":"Arthur Abrego"},"license":"MIT","_id":"@dj_abstract/mcp-audit@0.3.0","maintainers":[{"name":"dj_abstract","email":"abrego.arthur@gmail.com"}],"homepage":"https://github.com/abregoarthur-star/mcp-audit#readme","bugs":{"url":"https://github.com/abregoarthur-star/mcp-audit/issues"},"bin":{"mcp-audit":"bin/mcp-audit.js"},"dist":{"shasum":"56245240a7f788a442cec2fba1cd6f957302a10e","tarball":"https://registry.npmjs.org/@dj_abstract/mcp-audit/-/mcp-audit-0.3.0.tgz","fileCount":27,"integrity":"sha512-p4/zg2aKfp5ngCnYvcUSQnNbvJie/7Ju95OctxeGfQyNo3Hbm2uHlB+hkAaj4nz/RtATz9itQxeG+9WmwfvOYg==","signatures":[{"sig":"MEUCIDq3yOLJPjjLeihZJJJMndhfneLNo9vfOiinwrV1he86AiEArrf1QHAY2JEG1YIFwAciG7LUuiu99nc48Ct4ob5M9Ho=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":105066},"main":"src/index.js","type":"module","engines":{"node":">=20"},"exports":{".":"./src/index.js"},"gitHead":"7f32d539cff8351b707240a42278d7bb88a62369","scripts":{"test":"node --test 'test/**/*.test.js'","start":"node bin/mcp-audit.js","audit:self":"node bin/mcp-audit.js scan --manifest test/fixtures/sample-manifest.json","audit:brain":"node bin/mcp-audit.js scan --stdio 'node ../dj-abstract-ai-brain/src/agents/brain-tools-mcp.js'"},"_npmUser":{"name":"dj_abstract","email":"abrego.arthur@gmail.com"},"repository":{"url":"git+https://github.com/abregoarthur-star/mcp-audit.git","type":"git"},"_npmVersion":"11.6.2","description":"Security auditor for Model Context Protocol (MCP) servers — scans tool definitions for prompt injection, tool poisoning, unsafe combinations, and other AI-native vulnerabilities.","directories":{},"_nodeVersion":"25.2.1","dependencies":{"kleur":"^4.1.5","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-audit_0.3.0_1776495736585_0.8571433071422565","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@dj_abstract/mcp-audit","version":"0.3.1","keywords":["mcp","model-context-protocol","security","audit","ai-security","prompt-injection","tool-poisoning","llm-security","agent-security"],"author":{"name":"Arthur Abrego"},"license":"MIT","_id":"@dj_abstract/mcp-audit@0.3.1","maintainers":[{"name":"dj_abstract","email":"abrego.arthur@gmail.com"}],"homepage":"https://github.com/abregoarthur-star/mcp-audit#readme","bugs":{"url":"https://github.com/abregoarthur-star/mcp-audit/issues"},"bin":{"mcp-audit":"bin/mcp-audit.js"},"dist":{"shasum":"e6a102eaca51f5702c526101082d7dcf6a021d78","tarball":"https://registry.npmjs.org/@dj_abstract/mcp-audit/-/mcp-audit-0.3.1.tgz","fileCount":27,"integrity":"sha512-fj320ChHyHr3uew8H6SnohBoduVUhqDRDsGNVy0SNX9FeLpmP1VRTRYedNZVdtaVIf2O3DtS3iwmj4zKJp620Q==","signatures":[{"sig":"MEYCIQDEiNU+sW1wkVpdw2oVyQIYcqImaRmA+GxJb22RRW5skQIhAPgm/+gacGhD99a6Gi5xFw8C8kf+Wf9v5+ZG15TrMqFr","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":105560},"main":"src/index.js","type":"module","engines":{"node":">=20"},"exports":{".":"./src/index.js"},"gitHead":"08ac602816ed14a6f8006009ecb3e54a0c7b77bd","scripts":{"test":"node --test 'test/**/*.test.js'","start":"node bin/mcp-audit.js","audit:self":"node bin/mcp-audit.js scan --manifest test/fixtures/sample-manifest.json","audit:brain":"node bin/mcp-audit.js scan --stdio 'node ../dj-abstract-ai-brain/src/agents/brain-tools-mcp.js'"},"_npmUser":{"name":"dj_abstract","email":"abrego.arthur@gmail.com"},"repository":{"url":"git+https://github.com/abregoarthur-star/mcp-audit.git","type":"git"},"_npmVersion":"11.6.2","description":"Security auditor for Model Context Protocol (MCP) servers — scans tool definitions for prompt injection, tool poisoning, unsafe combinations, and other AI-native vulnerabilities.","directories":{},"_nodeVersion":"25.2.1","dependencies":{"kleur":"^4.1.5","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-audit_0.3.1_1776495814977_0.14848805184207992","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@dj_abstract/mcp-audit","version":"0.4.0","description":"Security auditor for Model Context Protocol (MCP) servers — scans tool definitions for prompt injection, tool poisoning, unsafe combinations, and other AI-native vulnerabilities.","type":"module","bin":{"mcp-audit":"bin/mcp-audit.js"},"main":"src/index.js","exports":{".":"./src/index.js"},"scripts":{"start":"node bin/mcp-audit.js","test":"node --test 'test/**/*.test.js'","audit:brain":"node bin/mcp-audit.js scan --stdio 'node ../dj-abstract-ai-brain/src/agents/brain-tools-mcp.js'","audit:self":"node bin/mcp-audit.js scan --manifest test/fixtures/sample-manifest.json"},"repository":{"type":"git","url":"git+https://github.com/abregoarthur-star/mcp-audit.git"},"bugs":{"url":"https://github.com/abregoarthur-star/mcp-audit/issues"},"homepage":"https://github.com/abregoarthur-star/mcp-audit#readme","keywords":["mcp","model-context-protocol","security","audit","ai-security","prompt-injection","tool-poisoning","llm-security","agent-security"],"author":{"name":"Arthur Abrego"},"license":"MIT","engines":{"node":">=20"},"dependencies":{"@modelcontextprotocol/sdk":"^1.29.0","kleur":"^4.1.5"},"gitHead":"f1ecfe2e729fd46da7e4a7a2424b4342d67aab61","_id":"@dj_abstract/mcp-audit@0.4.0","_nodeVersion":"25.2.1","_npmVersion":"11.6.2","dist":{"integrity":"sha512-/1n4DWjLM2lF5bEJZwq1zdP4rqBYM8zG26f1pJktJCWiiuGCRR8GG+SRu3mFUeRYPv1BGqknLwFt+KWGYsG2Jw==","shasum":"6ce51203a30c9f0f3617ea86082b855ed6cf1a86","tarball":"https://registry.npmjs.org/@dj_abstract/mcp-audit/-/mcp-audit-0.4.0.tgz","fileCount":28,"unpackedSize":118671,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGiEOsm2qlCy2mgdhLaqIPF0Z/FePVaRtA//DOeSPLAiAiApHlxB55+EDLUz1hpKIU23D3/lPxOheEauHOoxmX0cug=="}]},"_npmUser":{"name":"dj_abstract","email":"abrego.arthur@gmail.com"},"directories":{},"maintainers":[{"name":"dj_abstract","email":"abrego.arthur@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-audit_0.4.0_1776658103381_0.14518531515624877"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-18T04:02:54.902Z","modified":"2026-04-20T04:08:23.699Z","0.1.0":"2026-04-18T04:02:55.130Z","0.2.0":"2026-04-18T05:57:06.957Z","0.3.0":"2026-04-18T07:02:16.726Z","0.3.1":"2026-04-18T07:03:35.131Z","0.4.0":"2026-04-20T04:08:23.586Z"},"bugs":{"url":"https://github.com/abregoarthur-star/mcp-audit/issues"},"author":{"name":"Arthur Abrego"},"license":"MIT","homepage":"https://github.com/abregoarthur-star/mcp-audit#readme","keywords":["mcp","model-context-protocol","security","audit","ai-security","prompt-injection","tool-poisoning","llm-security","agent-security"],"repository":{"type":"git","url":"git+https://github.com/abregoarthur-star/mcp-audit.git"},"description":"Security auditor for Model Context Protocol (MCP) servers — scans tool definitions for prompt injection, tool poisoning, unsafe combinations, and other AI-native vulnerabilities.","maintainers":[{"name":"dj_abstract","email":"abrego.arthur@gmail.com"}],"readme":"# mcp-audit\n\n[![npm version](https://img.shields.io/npm/v/@dj_abstract/mcp-audit.svg?color=cb3837&logo=npm)](https://www.npmjs.com/package/@dj_abstract/mcp-audit)\n[![license: MIT](https://img.shields.io/badge/license-MIT-blue.svg)](./LICENSE)\n[![Node.js >=20](https://img.shields.io/badge/node-%3E%3D20-brightgreen.svg)](https://nodejs.org/)\n\nA security auditor for **Model Context Protocol (MCP)** servers. Scans tool, resource, and prompt definitions for AI-native security issues — prompt injection, tool poisoning, dangerous capability combinations, schema permissiveness, and more.\n\n> Why this exists: MCP servers ship arbitrary text directly into the host LLM's context. A malicious or sloppy server can manipulate any agent that connects to it. As the MCP ecosystem grows, the surface for prompt injection, tool poisoning, and \"lethal trifecta\" capability combinations grows with it. There's no shortage of CVE scanners. There's almost nothing focused on the threats that are unique to agent infrastructure.\n\n## What it checks\n\n| Rule | Severity (worst case) | What it catches |\n|------|-----------------------|------------------|\n| `prompt-injection` | critical | Instruction overrides, role redefinition, fake system tags, system-prompt extraction, silent-exfiltration directives, and other injection patterns embedded in tool/prompt/resource descriptions. |\n| `invisible-instructions` | critical | Unicode Tag block characters (the \"ASCII Smuggler\" attack), zero-width characters, control characters, and large base64 blobs hidden in descriptions. |\n| `tool-poisoning` | high | Hidden capabilities (params not mentioned in the description), read-only claims contradicted by mutating params, descriptions that reference a different tool name. |\n| `unsafe-tool-combos` | critical | \"Lethal trifecta\" combinations on a single server: shell-exec + network-egress, file-read + network-egress, secret-read + network-egress, file-write + shell-exec. |\n| `sensitive-output` | high | Tools whose names suggest they return secrets, env vars, credentials, sessions, or private keys. |\n| `destructive-no-confirm` | medium | Destructive tools (`delete_*`, `drop_*`, `kill_*`) with no confirmation parameter. |\n| `schema-permissiveness` | high | Unbounded string params on command-shaped surfaces, missing `inputSchema`, `additionalProperties: true`, undefined object structures. |\n| `unauthenticated-server` | high | Remote (HTTP/SSE) MCP servers that accept connections without auth. |\n| `excessive-scope` | medium | A single server spanning many unrelated capability domains (filesystem + network + shell + db + …) — large blast radius if compromised. |\n\n## Install\n\nOne-shot with `npx` (no install):\n\n```bash\nnpx @dj_abstract/mcp-audit scan --stdio \"node ./my-mcp-server.js\"\n```\n\nGlobal install:\n\n```bash\nnpm install -g @dj_abstract/mcp-audit\nmcp-audit --help\n```\n\nOr clone and run from source:\n\n```bash\ngit clone https://github.com/abregoarthur-star/mcp-audit\ncd mcp-audit\nnpm install\nnode bin/mcp-audit.js --help\n```\n\nRequires Node.js 20+.\n\n## Usage\n\n### Scan a local stdio MCP server\n\n```bash\nmcp-audit scan --stdio \"node ./my-mcp-server.js\"\n```\n\n### Scan a remote HTTP/SSE server\n\n```bash\nmcp-audit scan --url https://mcp.example.com/sse --bearer \"$TOKEN\"\nmcp-audit scan --url https://mcp.example.com --header \"X-Api-Key: $KEY\"\n```\n\n### Scan a static manifest\n\nUseful for offline audits, CI pipelines, or auditing in-process SDK servers (see \"Auditing Agent SDK servers\" below).\n\n```bash\nmcp-audit scan --manifest server.json\n```\n\n### Output formats\n\n```bash\nmcp-audit scan --stdio \"...\" --html report.html        # standalone HTML, share-friendly\nmcp-audit scan --stdio \"...\" --json report.json        # JSON for CI / automation\nmcp-audit scan --stdio \"...\" --sarif results.sarif     # SARIF 2.1.0 — GitHub code-scanning compatible\nmcp-audit scan --stdio \"...\" --json                    # JSON to stdout\nmcp-audit scan --stdio \"...\" --quiet --json | jq ...   # piping\n```\n\n### CI gate\n\nExit non-zero if any finding meets a severity threshold:\n\n```bash\nmcp-audit scan --stdio \"...\" --fail-on high\n```\n\n### GitHub Actions (native Code Scanning integration)\n\nDrop-in Action that runs the scan, emits SARIF, and surfaces findings in your PR's Security tab and inline on Files Changed:\n\n```yaml\n- uses: abregoarthur-star/mcp-audit-action@v1\n  with:\n    manifest: ./mcp-manifest.json\n    fail-on: high\n```\n\nFull docs and recipes: [mcp-audit-action](https://github.com/abregoarthur-star/mcp-audit-action).\n\n## Auditing Agent SDK servers\n\nServers built with the Anthropic Agent SDK's `createSdkMcpServer()` run in-process; they are not standalone stdio servers. Use the bundled extractor to dump them as a manifest first:\n\n```bash\nnode bin/extract-sdk-server.js path/to/your-mcp.js exportName /tmp/manifest.json\nmcp-audit scan --manifest /tmp/manifest.json --html report.html\n```\n\n## Sample finding\n\n```\n CRITICAL  Shell execution + network egress on same server\n  rule: unsafe-tool-combos  ·  target: server/brain-tools\n  A single server provides both arbitrary command execution and outbound\n  network capability. Any prompt-injection that lands here can run a\n  command and exfiltrate the output in one hop.\n  evidence:\n    shell_exec: [\"execute_command\"]\n    network_out: [\"create_linkedin_draft\",\"security_intel\",\"market_intel\",\n                  \"send_telegram\",\"manage_tasks\",\"read_email\",\"send_email\"]\n  remediation:\n    Split capabilities across separate MCP servers with separate trust\n    boundaries. The host agent can compose them, but a compromise of one\n    server should not yield the full kill chain.\n  refs:\n    - https://owasp.org/www-project-top-10-for-large-language-model-applications/\n    - https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/\n```\n\n## Threat model\n\n`mcp-audit` is a **static analyzer** of an MCP server's surface. It does not execute tools, send payloads, or attempt exploitation. Every check is read-only:\n\n- For **stdio** servers: spawn the server, perform the MCP `initialize`/`tools/list`/`resources/list`/`prompts/list` handshakes, then close.\n- For **HTTP/SSE** servers: connect, list, close.\n- For **manifests**: pure file read.\n\nThis makes it safe to run against production servers, including third-party servers you don't own.\n\nIt will not catch:\n\n- Vulnerabilities in tool **implementations** (e.g. SQL injection inside a `query_db` handler).\n- Behavior that only manifests at call time (e.g. rate-limit issues, time-of-check / time-of-use bugs).\n- Backdoored binaries or supply-chain compromise of the server itself.\n\nPair it with conventional SAST/DAST and supply-chain scanning.\n\n## Differential audits (`diff`)\n\nDetect **rug-pulls and drift** between two snapshots of an MCP server. New to `0.3.0`.\n\n```bash\n# First time — save a baseline\nmcp-audit scan --stdio \"...\" --json baseline.json\n\n# Later — diff current state against baseline\nmcp-audit diff baseline.json current.json\nmcp-audit diff baseline.json current.json --fail-on high   # CI gate\n```\n\nWhat it catches:\n\n| Severity | Detects |\n|---|---|\n| **CRITICAL** | A new tool introduces a capability class (shell-exec, network-egress, secret-read) the server didn't have before — silent capability expansion, classic rug-pull. |\n| **CRITICAL** | Prompt-injection markers appeared in a tool description that wasn't there before. |\n| **CRITICAL** | An existing tool's capability class widened (e.g. its name or schema now implies shell execution where it previously didn't). |\n| **HIGH** | Server-level capability drift — the union of the server's capabilities has grown. |\n| **HIGH** | `readOnlyHint` annotation removed — a previously read-only tool can now mutate state. |\n| **HIGH** | `inputSchema` widened with `additionalProperties: true`. |\n| **HIGH** | Tool description materially rewritten (>25% length delta). |\n| **MEDIUM** | New tool added (no new capability class). |\n| **MEDIUM** | Tool removed. |\n| **MEDIUM** | Required parameters dropped from `inputSchema`. |\n| **LOW** | Cosmetic description or schema edits. |\n\nPair with CI: if you connect your agent to a third-party MCP server, run `mcp-audit scan --json current.json` nightly and `mcp-audit diff prior.json current.json --fail-on high` to page on silent changes. Your agents should not discover a new `execute_command` tool on a server they've trusted for months.\n\n## Programmatic API\n\n```javascript\nimport { audit, diff } from '@dj_abstract/mcp-audit';\n\n// Scan\nconst report = await audit({ stdio: 'node ./server.js' });\nconsole.log(report.summary.bySeverity);\n\n// Diff\nconst result = await diff('baseline.json', 'current.json');\nconsole.log(result.summary, result.changes);\nfor (const f of result.findings) {\n  console.log(f.severity, f.ruleId, f.title);\n}\n```\n\n## Roadmap\n\n- Detection-only Nuclei-style remote checks (auth bypass probes, CORS misconfig)\n- Per-tool permission-cost scoring (rank which tools deserve human-in-the-loop gating)\n- Integration with the [MCP server registry](https://modelcontextprotocol.io/) for community scoring\n- Recipe for Brain Agent SDK to call `audit()` before connecting to any new server\n\n## References\n\n- [OWASP Top 10 for LLM Applications](https://owasp.org/www-project-top-10-for-large-language-model-applications/)\n- [Tool Poisoning Attacks (Invariant Labs)](https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks)\n- [The Lethal Trifecta (Simon Willison)](https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/)\n- [Hiding and finding text with Unicode Tags (Embrace The Red)](https://embracethered.com/blog/posts/2024/hiding-and-finding-text-with-unicode-tags/)\n- [MITRE ATLAS](https://atlas.mitre.org/)\n- [Model Context Protocol specification](https://modelcontextprotocol.io/)\n\n## Related tools\n\nPart of a **detect → inventory → test → generate → defend** pipeline for AI-agent security:\n\n| Layer | Tool | Role |\n|---|---|---|\n| Detect | **mcp-audit** *(you are here)* | Static audit of MCP server definitions |\n| Detect | [`mcp-audit-sweep`](https://github.com/abregoarthur-star/mcp-audit-sweep) | Reproducible sweep of public MCP servers (methodology + report) |\n| Inventory | [`@dj_abstract/agent-capability-inventory`](https://github.com/abregoarthur-star/agent-capability-inventory) | Fleet-wide tool catalog with data-sensitivity tags |\n| Test | [`prompt-eval`](https://github.com/abregoarthur-star/prompt-eval) | Runtime prompt-injection eval harness against a live agent |\n| Generate | [`@dj_abstract/prompt-genesis`](https://github.com/abregoarthur-star/prompt-genesis) | LLM-driven adversarial attack corpus generator (feeds prompt-eval) |\n| Defend | [`@dj_abstract/agent-firewall`](https://github.com/abregoarthur-star/agent-firewall) | Call-time defensive middleware for tool invocations |\n\n## License\n\nMIT — see [LICENSE](./LICENSE).\n","readmeFilename":"README.md"}