mcp-audit
Static security + correctness audit for MCP server repos.
pip install mcp-audit
mcp-audit # scan the current directory
mcp-audit /path/to/repo # scan a specific repo
mcp-audit --json # machine-readable output
mcp-audit --check fastmcp_wrapper_layer # one check only
mcp-audit --list-checks # list available checks
Exit codes: 0 clean, 1 at least one finding, 2 usage error.
What it checks
| Check ID | Severity | What it finds |
|---|---|---|
starlette_badhost |
HIGH / MED | Starlette < 1.0.1 in pyproject.toml, requirements*.txt, uv.lock, poetry.lock, pdm.lock. BadHost (CVE-2026-48710) lets a crafted HTTP Host header bypass path-based authorization. Affects any HTTP/SSE-transport MCP server. Stdio servers are unaffected. |
fastmcp_wrapper_layer |
HIGH | Sync @mcp.tool() functions that call asyncio.run(...) inside their body. FastMCP invokes tools inside an already-running event loop; asyncio.run() raises RuntimeError. Looks fine in unit tests, dies on the first real protocol call. |
tool_input_validation |
LOW | @mcp.tool() parameters typed as bare str / bytes / Any / list[Any] / dict[..., Any] or with no annotation at all. The schema FastMCP exposes to the LLM is the substrate prompt-injection-via-tool-description attacks rely on; constraining it (Annotated[str, Field(max_length=N)], Literal[...], Pydantic models) closes the window without losing expressiveness. Hygiene check, not a CVE — expect findings even on well-written servers. Added in v0.2. |
command_injection |
HIGH | @mcp.tool() functions where a tool parameter (or a local tainted via assignment / .format() / string concat) flows into os.system, os.popen, or subprocess.* with shell=True or a tainted-interpolated command string. v0.4 added same-file cross-function taint propagation: the analyzer now follows local helper calls (positional + keyword binding, recursion-visited guard), so tool -> helper -> sink flows are caught. Cross-file taint remains out of scope. The list-of-args / no-shell pattern is correctly NOT flagged. Added in v0.3, cross-function in v0.4. |
destructive_fs_sink |
MEDIUM | @mcp.tool() functions where a tool parameter flows into a destructive filesystem call — shutil.rmtree, os.remove / os.unlink / os.rmdir / os.removedirs, or Path.unlink() / Path.rmdir() — with no path-containment guard, letting a caller delete arbitrary paths the server can reach. Suppressed when the function canonicalizes-and-confines the path (realpath/resolve + startswith/relative_to) or checks it against a server-managed allow-set — a deliberate false-negative bias. Found the unguarded shutil.rmtree(directory) in manim-mcp-server's cleanup_manim_temp_dir that the other four checks all miss. Added in v0.7. |
More checks are landing — hard-coded secrets, write-API tools missing a FORBIDDEN_NAMES-style guardrail, read-only-by-default violations (e.g. SQL read-only enforced by keyword prefix rather than a real read-only connection), path traversal in filesystem-touching servers.
Output format
$ mcp-audit examples/bad/
[HIGH ] starlette_badhost @ uv.lock
uv lockfile pins starlette==0.36.3 — vulnerable to BadHost (CVE-2026-48710). Patched in 1.0.1.
-> Upgrade Starlette to >=1.0.1 (the BadHost patch). If FastAPI pulls Starlette transitively, pin it explicitly. ...
[HIGH ] fastmcp_wrapper_layer @ server.py:18
tool 'fetch_url' (def) calls asyncio.run() inside its body. FastMCP invokes tools inside an already-running event loop, and asyncio.run() raises RuntimeError when nested. This will fail at the first real MCP protocol call even if every unit test passes.
-> Convert the tool to `async def` and replace `asyncio.run(...)` with `await`. ...
mcp-audit: 2 finding(s) — 2 high
--json emits one object: {"root": "...", "finding_count": N, "findings": [...]}. Each finding has check, severity, path, line, message, remediation.
What this is not
- It is not a runtime sandbox. Static analysis only.
- It does not install your venv to introspect it. It reads what's declared (manifests + lockfiles + source).
- It will not detect every vulnerability — only the classes its checks know about. Treat zero findings as "no known issues from this tool," not as a clean bill.
Background
- BadHost write-up: https://mcpdone.com/blog/badhost-mcp-servers
- FastMCP wrapper-layer bug write-up: https://mcpdone.com/blog/fastmcp-wrapper-layer-bug
Development
git clone https://github.com/Alienbushman/mcpdone-samples
cd mcpdone-samples/mcp-audit
pip install -e ".[dev]"
pytest
python smoke_test.py
To add a check: drop src/mcp_audit/checks/<name>.py exposing a module-level CHECK_ID and a check(root: Path) -> list[Finding] callable. Register it in src/mcp_audit/checks/__init__.py. Add fixtures + tests under tests/.
License
MIT.
Release files for mcpdone-audit 0.7.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| mcpdone_audit-0.7.0.tar.gz | 29.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| mcpdone_audit-0.7.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 56.3 kB
Release files / mcpdone_audit-0.7.0.tar.gz
| Download URL | mcpdone_audit-0.7.0.tar.gz |
|---|---|
| Size | 29.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
8fcf9e147010d00171f9369c0d84aaa6f948388f8f2830a2fffcb397e5ec6043
|
|
BLAKE2b-256 checksum How to use checksums |
3c20d84968251ed18d06072a34cbc92a90ad9394b9858a38808c505c439b6767
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 21, 2026.
Transparency logRelease files / mcpdone_audit-0.7.0-py3-none-any.whl
| Download URL | mcpdone_audit-0.7.0-py3-none-any.whl |
|---|---|
| Size | 26.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ee6f7df74c854ca80af6b959801744b6f89effcb2bf33fcd36184c0b91e52c8f
|
|
BLAKE2b-256 checksum How to use checksums |
e731f5e698dad13162f5d668f5fc61af122c3e0c48af7b90907d007e8f0628a1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 21, 2026.
Transparency log