{"_id":"@dutjr1/mcpwatch","_rev":"8-cfe37043627ddaa3859affe630b198df","name":"@dutjr1/mcpwatch","dist-tags":{"latest":"0.8.0"},"versions":{"0.3.0":{"name":"@dutjr1/mcpwatch","version":"0.3.0","keywords":["mcp","model-context-protocol","security","scanner","llm","ai-agents"],"license":"Apache-2.0","_id":"@dutjr1/mcpwatch@0.3.0","maintainers":[{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"}],"homepage":"https://github.com/DUTJR1/mcpwatch#readme","bugs":{"url":"https://github.com/DUTJR1/mcpwatch/issues"},"bin":{"mcpwatch":"dist/cli.js"},"dist":{"shasum":"3a86db86a116587a074b361848dedc13503bdf88","tarball":"https://registry.npmjs.org/@dutjr1/mcpwatch/-/mcpwatch-0.3.0.tgz","fileCount":94,"integrity":"sha512-rd2+v7MJQTcUVbFmqs6sjEr45EQu35GYCGn55tOE/+ED9mmjTjwkGrXW2OCXGPEP2V9DqP1xLtyV1e7UxU9Y8Q==","signatures":[{"sig":"MEUCIEWEWd1An8QlmdUlI/CThxebFfSrwTMaNxebPpxD1G9aAiEAlBEhFF5vpW60orvDVwkpewIH7R7xVdCJ6tDAugNgEFA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":124548},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"e19452fb84fff7fa5766c0b6fa4199c49b001f14","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","scan:self":"node dist/cli.js scan ."},"_npmUser":{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"},"repository":{"url":"git+https://github.com/DUTJR1/mcpwatch.git","type":"git"},"_npmVersion":"11.17.0","description":"Security scanner for MCP (Model Context Protocol) servers and configurations","directories":{},"_nodeVersion":"24.19.0","dependencies":{"ajv":"^8.17.1","openai":"^5.0.0","commander":"^12.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.5.4","@types/node":"^22.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcpwatch_0.3.0_1787553100577_0.08648648235092482","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@dutjr1/mcpwatch","version":"0.4.0","keywords":["mcp","model-context-protocol","security","scanner","llm","ai-agents"],"license":"Apache-2.0","_id":"@dutjr1/mcpwatch@0.4.0","maintainers":[{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"}],"homepage":"https://github.com/DUTJR1/mcpwatch#readme","bugs":{"url":"https://github.com/DUTJR1/mcpwatch/issues"},"bin":{"mcpwatch":"dist/cli.js"},"dist":{"shasum":"10ecf395a544aa696ff6b23373e81f5502ddc145","tarball":"https://registry.npmjs.org/@dutjr1/mcpwatch/-/mcpwatch-0.4.0.tgz","fileCount":97,"integrity":"sha512-YfE3hgxvT1vP5ktMAMfqUMM75GKkTN/PCxCWMPrrSmR1Kr45trf28uX3cnyKCXscWdCCF86HRsVO11PezW2F9g==","signatures":[{"sig":"MEUCIQCmQf/o/ODRP9tu8aYOTB8dX5/Vd+LiHxS3xQzpYwsW4AIgGQfH3orcNvj2+0Ue7lyoJNBfBUMZMsQDGHWPu/lqHmY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":148618},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"11bc9ae2abcb738f09562f371f9051067ad12922","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","scan:self":"node dist/cli.js scan ."},"_npmUser":{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"},"repository":{"url":"git+https://github.com/DUTJR1/mcpwatch.git","type":"git"},"_npmVersion":"11.17.0","description":"Security scanner for MCP (Model Context Protocol) servers and configurations","directories":{},"_nodeVersion":"24.19.0","dependencies":{"ajv":"^8.17.1","openai":"^5.0.0","commander":"^12.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.5.4","@types/node":"^22.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcpwatch_0.4.0_1787562658196_0.5710339413140362","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@dutjr1/mcpwatch","version":"0.5.0","keywords":["mcp","model-context-protocol","security","scanner","llm","ai-agents"],"license":"Apache-2.0","_id":"@dutjr1/mcpwatch@0.5.0","maintainers":[{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"}],"homepage":"https://github.com/DUTJR1/mcpwatch#readme","bugs":{"url":"https://github.com/DUTJR1/mcpwatch/issues"},"bin":{"mcpwatch":"dist/cli.js"},"dist":{"shasum":"01c8895461989c6144c186f7f8fed05c8e09a8b0","tarball":"https://registry.npmjs.org/@dutjr1/mcpwatch/-/mcpwatch-0.5.0.tgz","fileCount":103,"integrity":"sha512-Sf3kws1eQb7ogZ3iBHnGtYWundsovMjKVRO5zsg3Vg7iOSBuna+jXK6Z/fybVb3fBM9jZQO8rpelaeNahq1e4Q==","signatures":[{"sig":"MEQCIByEtYxVzm/32u9g59xdMIcbYfapM7QF/fHYYILd79OEAiBwPcB2ElJwTkLDq8vKSDdIe/ba/KDvQImKVltJZlTG1w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":178477},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"3039d6850f7b4a54585bae6dbb7d37b83ba18530","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","scan:self":"node dist/cli.js scan ."},"_npmUser":{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"},"repository":{"url":"git+https://github.com/DUTJR1/mcpwatch.git","type":"git"},"_npmVersion":"10.9.7","description":"Security scanner for MCP (Model Context Protocol) servers and configurations","directories":{},"_nodeVersion":"22.22.2","dependencies":{"ajv":"^8.17.1","openai":"^5.0.0","commander":"^12.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.5.4","@types/node":"^22.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcpwatch_0.5.0_1787625713010_0.419323949579425","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@dutjr1/mcpwatch","version":"0.6.0","keywords":["mcp","model-context-protocol","security","scanner","llm","ai-agents"],"license":"Apache-2.0","_id":"@dutjr1/mcpwatch@0.6.0","maintainers":[{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"}],"homepage":"https://github.com/DUTJR1/mcpwatch#readme","bugs":{"url":"https://github.com/DUTJR1/mcpwatch/issues"},"bin":{"mcpwatch":"dist/cli.js"},"dist":{"shasum":"bd5f245404a29fbde141053f97406a534d345d1e","tarball":"https://registry.npmjs.org/@dutjr1/mcpwatch/-/mcpwatch-0.6.0.tgz","fileCount":163,"integrity":"sha512-8+xIVVjBSRiMNDoy2keOjzTsrVUMrtjVIVlWI+r7GY517CSHaYK3mBM7/x6yFFAJwu+Ee9merYYd181eqO4jJQ==","signatures":[{"sig":"MEQCIDOrwNkP+pL6+x/dyItJtSkZcS6S6J3soKu9YXN3aI8UAiAeGeiZPWWO9Bz/8iiqj+M1H2xr4gruv7zpRAYlN5h8aQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":241535},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"ef6e8be506c6c02c5425a87137574111e4f3f631","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","scan:self":"node dist/cli.js scan ."},"_npmUser":{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"},"repository":{"url":"git+https://github.com/DUTJR1/mcpwatch.git","type":"git"},"_npmVersion":"10.9.7","description":"Security scanner for MCP (Model Context Protocol) servers and configurations","directories":{},"_nodeVersion":"22.22.2","dependencies":{"ajv":"^8.17.1","openai":"^5.0.0","commander":"^12.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.5.4","@types/node":"^22.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcpwatch_0.6.0_1787650119640_0.6712921553806515","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"@dutjr1/mcpwatch","version":"0.6.1","keywords":["mcp","model-context-protocol","security","scanner","llm","ai-agents"],"license":"Apache-2.0","_id":"@dutjr1/mcpwatch@0.6.1","maintainers":[{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"}],"homepage":"https://github.com/DUTJR1/mcpwatch#readme","bugs":{"url":"https://github.com/DUTJR1/mcpwatch/issues"},"bin":{"mcpwatch":"dist/cli.js"},"dist":{"shasum":"7691e1916a1be6ccde0f65192f10162a91abc60f","tarball":"https://registry.npmjs.org/@dutjr1/mcpwatch/-/mcpwatch-0.6.1.tgz","fileCount":166,"integrity":"sha512-0eblLRvAXuXmMExPI2xcUYLYXyMryiEP55dp+Julvo+XKf1s4LhrIZLTzZ80E8M3Y2N6nBzV+DgnMYfVPp3Vng==","signatures":[{"sig":"MEYCIQCVxJt0Tmj5E8yD/HrArz751yV0Bynpxac6aPhc2BN8BwIhAJBK3wUynrlp5qvJPHaFTIzjz6MYuYcy43L/vJC2EjIE","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":264190},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"18738e662fe56c70f8ae30f8877d760c8bd6b6b6","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","scan:self":"node dist/cli.js scan ."},"_npmUser":{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"},"repository":{"url":"git+https://github.com/DUTJR1/mcpwatch.git","type":"git"},"_npmVersion":"10.9.7","description":"Security scanner for MCP (Model Context Protocol) servers and configurations","directories":{},"_nodeVersion":"22.22.2","dependencies":{"ajv":"^8.17.1","openai":"^5.0.0","commander":"^12.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.5.4","@types/node":"^22.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcpwatch_0.6.1_1787720891123_0.12406005475691817","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@dutjr1/mcpwatch","version":"0.7.0","keywords":["mcp","model-context-protocol","security","scanner","llm","ai-agents"],"license":"Apache-2.0","_id":"@dutjr1/mcpwatch@0.7.0","maintainers":[{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"}],"homepage":"https://github.com/DUTJR1/mcpwatch#readme","bugs":{"url":"https://github.com/DUTJR1/mcpwatch/issues"},"bin":{"mcpwatch":"dist/cli.js"},"dist":{"shasum":"7f89b807ffb25031b36c3458b569fcb530c4eda3","tarball":"https://registry.npmjs.org/@dutjr1/mcpwatch/-/mcpwatch-0.7.0.tgz","fileCount":166,"integrity":"sha512-kR3x/I+kfpLHKK1vfylmuWJcDzoPjlDvnzw7qlZVAtcG6nPoSkIcjeJYOUC7TlyirxUmBVeeFgvituuWIdkUNg==","signatures":[{"sig":"MEQCIH3YvRcUnD533ex1jShFOBSA6zVTvZuZpZGD954h2iGVAiBIpzwBHF3UzjyjxXK+uUgu0jJmPTQu87iMP8LJRVVBrQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":267123},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"cad4bee2cdb7299ca4289f164da5a3c8f5f1de25","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","scan:self":"node dist/cli.js scan ."},"_npmUser":{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"},"repository":{"url":"git+https://github.com/DUTJR1/mcpwatch.git","type":"git"},"_npmVersion":"10.9.7","description":"Security scanner for MCP (Model Context Protocol) servers and configurations","directories":{},"_nodeVersion":"22.22.2","dependencies":{"ajv":"^8.17.1","openai":"^5.0.0","commander":"^12.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.5.4","@types/node":"^22.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcpwatch_0.7.0_1787731303938_0.38330608107365727","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"@dutjr1/mcpwatch","version":"0.7.1","keywords":["mcp","model-context-protocol","security","scanner","llm","ai-agents"],"license":"Apache-2.0","_id":"@dutjr1/mcpwatch@0.7.1","maintainers":[{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"}],"homepage":"https://github.com/DUTJR1/mcpwatch#readme","bugs":{"url":"https://github.com/DUTJR1/mcpwatch/issues"},"bin":{"mcpwatch":"dist/cli.js"},"dist":{"shasum":"8e7195e3d241ae83a5a3dd5a901d38369b0867f6","tarball":"https://registry.npmjs.org/@dutjr1/mcpwatch/-/mcpwatch-0.7.1.tgz","fileCount":166,"integrity":"sha512-57VHW0d4IM2KFbD7xVEf3Tq5U1ne4ERc20YYVOss+J5eOCB2QXcbNplkO5RAI9/pnueM1UUQQPoCpcvn9xve8w==","signatures":[{"sig":"MEYCIQDzW1i6K55xHXHk5Ccep+pc2Bg1pc1YS0ETfrmLX8W8/AIhAJqmLYS8+lcZavfR5K56y012PfluarRGpV7fjx34imwV","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":270497},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"425a061bfbe36c946e7c42769e6ab73eceef7f38","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","scan:self":"node dist/cli.js scan ."},"_npmUser":{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"},"repository":{"url":"git+https://github.com/DUTJR1/mcpwatch.git","type":"git"},"_npmVersion":"10.9.7","description":"Security scanner for MCP (Model Context Protocol) servers and configurations","directories":{},"_nodeVersion":"22.22.2","dependencies":{"ajv":"^8.17.1","openai":"^5.0.0","commander":"^12.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.5.4","@types/node":"^22.5.0"},"_npmOperationalInternal":{"tmp":"tmp/mcpwatch_0.7.1_1787739630794_0.7041803708393182","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"_id":"@dutjr1/mcpwatch@0.8.0","bin":{"mcpwatch":"dist/cli.js"},"bugs":{"url":"https://github.com/DUTJR1/mcpwatch/issues"},"dist":{"shasum":"504864b0ae4f81825e9c584247013870d2a3d8d7","tarball":"https://registry.npmjs.org/@dutjr1/mcpwatch/-/mcpwatch-0.8.0.tgz","fileCount":169,"integrity":"sha512-u7mCTBaVoFTGcNSF1afjC3QedN+tTNfu4b+kLTY+kTZXUfQCn4hCVgd/FlYK8cue3tlvIkWZicccz/pAcemQsg==","signatures":[{"sig":"MEQCICDviy5yp1qIuHOSwnO/R9t6I9JMIrXokhg/Hio8Zsu2AiA6OOim5NdtVvwX+NLXoBPvsSLfgnE1/eScyTDubn442w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDxXTQT79W7cwuNEX8W97Cin6KtQRLAWZXILzLRSVRZMAIhAL8UInKU0DEscsTuKqMT2L9yQwHz0jw1tYo5sJfQYyZH"}],"unpackedSize":284803},"main":"./dist/index.js","name":"@dutjr1/mcpwatch","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"ff2afd21afb13d93c51f05fff2edd49feaf146e5","license":"Apache-2.0","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","scan:self":"node dist/cli.js scan ."},"version":"0.8.0","_npmUser":{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"},"homepage":"https://github.com/DUTJR1/mcpwatch#readme","keywords":["mcp","model-context-protocol","security","scanner","llm","ai-agents"],"repository":{"url":"git+https://github.com/DUTJR1/mcpwatch.git","type":"git"},"_npmVersion":"10.9.7","description":"Security scanner for MCP (Model Context Protocol) servers and configurations","directories":{},"maintainers":[{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"}],"_nodeVersion":"22.22.2","dependencies":{"ajv":"^8.17.1","openai":"^5.0.0","commander":"^12.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.5.4","@types/node":"^22.5.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcpwatch_0.8.0_1787900851451_0.42275346236824385"}}},"time":{"created":"2026-08-24T06:31:40.338Z","modified":"2026-08-28T07:07:31.704Z","0.3.0":"2026-08-24T06:31:40.723Z","0.4.0":"2026-08-24T09:10:58.328Z","0.5.0":"2026-08-25T02:41:53.156Z","0.6.0":"2026-08-25T09:28:39.784Z","0.6.1":"2026-08-26T05:08:11.259Z","0.7.0":"2026-08-26T08:01:44.083Z","0.7.1":"2026-08-26T10:20:30.957Z","0.8.0":"2026-08-28T07:07:31.544Z"},"bugs":{"url":"https://github.com/DUTJR1/mcpwatch/issues"},"license":"Apache-2.0","homepage":"https://github.com/DUTJR1/mcpwatch#readme","keywords":["mcp","model-context-protocol","security","scanner","llm","ai-agents"],"repository":{"url":"git+https://github.com/DUTJR1/mcpwatch.git","type":"git"},"description":"Security scanner for MCP (Model Context Protocol) servers and configurations","maintainers":[{"name":"dutjr1","email":"DUTJasonR.cn.1@gmail.com"}],"readme":"# mcpwatch\n\nSecurity scanner for MCP (Model Context Protocol) servers and configurations.\n\n[![CI](https://github.com/DUTJR1/mcpwatch/actions/workflows/ci.yml/badge.svg)](https://github.com/DUTJR1/mcpwatch/actions/workflows/ci.yml)\n[![npm version](https://img.shields.io/npm/v/mcpwatch)](https://www.npmjs.com/package/mcpwatch)\n[![npm downloads](https://img.shields.io/npm/dm/mcpwatch)](https://www.npmjs.com/package/mcpwatch)\n[![License](https://img.shields.io/badge/license-Apache--2.0-blue)](LICENSE)\n\nMCP has become the standard way AI agents connect to tools, files, and credentials.\nBut shipped MCP servers are routinely exposed to tool poisoning, prompt injection,\nand over-privileged scopes — and most projects have no security check in CI.\n\nmcpwatch scans MCP manifests, tool descriptions, and server code for these risks,\nlocally or in your CI pipeline.\n\n## Status\n\nEarly development. See [ROADMAP.md](ROADMAP.md) for the release plan and\n[CHANGELOG.md](CHANGELOG.md) for what has shipped.\n\n| Feature | Status |\n|---|---|\n| Static rule engine (41 rules, mapped to OWASP LLM Top 10) | shipped |\n| CLI: text / JSON / SARIF / HTML output | shipped |\n| GitHub Action with Code Scanning integration | shipped |\n| Self-contained HTML report (`--format html`) | shipped |\n| Optional LLM-assisted semantic analysis (bring your own key, MG900) | shipped |\n| Rug-pull detection: tool-description drift against a baseline (MG701–MG703) | shipped |\n| Auto-fix: safe rewrites for zero-width descriptions and http→https endpoints (MG004/MG012) | shipped |\n| Config file `.mcpwatchrc` / `.mcpwatchrc.json`: include/exclude paths, ignore rules, severity threshold, and a `failOn` CI gate | shipped |\n\n## Install\n\n```bash\nnpm install -g @dutjr1/mcpwatch\n# or run without installing\nnpx @dutjr1/mcpwatch scan .\n```\n\n## Quick start\n\n```bash\n# scan the current directory, human-readable output\nmcpwatch scan .\n\n# machine-readable output\nmcpwatch scan . --format json\n\n# SARIF for GitHub Code Scanning\nmcpwatch scan . --format sarif > results.sarif\n\n# self-contained HTML report (single file, inline CSS, no network needed)\nmcpwatch scan . --format html > report.html\n\n# capture a trust baseline, then detect rug-pull description drift\nmcpwatch baseline ./config\nmcpwatch scan ./config --baseline ./config\n\n# preview safe auto-fixes, then apply them (originals backed up to .bak)\nmcpwatch scan ./config --fix\nmcpwatch scan ./config --fix --yes\n```\n\nThe exit code is `1` when any error-severity finding is present, so it works\nas a CI gate.\n\n## Configuration\n\nmcpwatch can read a config file so you don't repeat flags on every run. Drop a\n`.mcpwatchrc` or `.mcpwatchrc.json` in your project root (or pass `--config\n<path>`), and it will control which files are scanned, which rules run, how\nloud the report is, and how strict the failure gate is:\n\n```bash\n# only scan src/, ignore MG012, and never fail the build on findings\nmcpwatch scan . --config .mcpwatchrc.json\n\n# one-off override of the failure gate\nmcpwatch scan . --fail-on warning\n```\n\nConfig options include `include` / `exclude` (path filtering),\n`ignoreRules` (with `MG0*` wildcards), a `severityThreshold`, `failOn`\n(`error` | `warning` | `info` | `none`), and `format`. A `_mcpwatch-ignore`\nkey or a `.mcpwatchignore` file offers inline rule silencing. The CLI flag\nalways wins over the file. Full schema, precedence rules, and GitHub Actions +\nGitLab CI recipes are in [docs/config.md](docs/config.md).\n\n## Use in GitHub Actions\n\nmcpwatch ships as a composite Action. Drop it into any repo's workflow to\nscan MCP servers and configs on every push or PR:\n\n```yaml\n- uses: DUTJR1/mcpwatch@v0.3\n  with:\n    path: \".\"\n    fail-on-error: true\n```\n\nIt writes `mcpwatch-results.sarif`. Pair it with\n[github/codeql-action/upload-sarif](https://github.com/github/codeql-action)\nto surface results in GitHub code scanning, or with\n[marocchino/sticky-pull-request-comment](https://github.com/marocchino/sticky-pull-request-comment)\nto post the report on PRs. Full recipes in [docs/action.md](docs/action.md).\n\n## How it works\n\nEvery check is a small rule with an id like `MG001`. Rules examine MCP config\nfiles, tool descriptions, and server source code. Each rule ships with a real\nattack sample it was built from — the full catalog lives in\n[docs/rules.md](docs/rules.md) (MG000–MG040, drift rules MG701–MG703, and the\nLLM-assisted MG900).\n\n## Ecosystem scan\n\nmcpwatch runs periodic scans of real open-source MCP servers to measure coverage, surface\ngenuine hardening gaps, and catch its own false positives. The 16-repo scan (7 official\n`modelcontextprotocol/servers` subdirs + 9 third-party servers) is reproducible from this\nrepository:\n\n```bash\n# clones/shallow-pulls the repo list, runs the production engine, writes the report\nbash scripts/scan-ecosystem.sh\n```\n\nThis produces `docs/ecosystem-report.md` (method, per-repo results table, by-rule and\nby-severity distributions, false-positive handling, and a comparison with the Invariant Labs\nMCP threat landscape and OWASP LLM Top 10) and the machine-readable\n`reference/ecosystem-results.json`. The repo list lives in `scripts/ecosystem-repos.json` and\nthe per-repo verdicts (every finding manually verified) in `scripts/ecosystem-verdicts.json`.\nLatest run: 16 repos / 2089 files / 982 findings in 3389 ms total. **No issues are filed\nagainst the scanned projects by this process — only draft reports are produced.**\n\n## Contributing\n\nSee [CONTRIBUTING.md](CONTRIBUTING.md). Bug reports and rule ideas are welcome\nin [issues](https://github.com/DUTJR1/mcpwatch/issues).\n\n## Security\n\nTo report a vulnerability in mcpwatch itself, see [SECURITY.md](SECURITY.md).\n\n## License\n\n[Apache-2.0](LICENSE)\n","readmeFilename":"README.md"}