Skip to main content

mcp-audit

Static security + correctness audit for MCP server repos.

pip install mcp-audit
mcp-audit                     # scan the current directory
mcp-audit /path/to/repo       # scan a specific repo
mcp-audit --json              # machine-readable output
mcp-audit --check fastmcp_wrapper_layer  # one check only
mcp-audit --list-checks       # list available checks

Exit codes: 0 clean, 1 at least one finding, 2 usage error.

What it checks

Check ID Severity What it finds
starlette_badhost HIGH / MED Starlette < 1.0.1 in pyproject.toml, requirements*.txt, uv.lock, poetry.lock, pdm.lock. BadHost (CVE-2026-48710) lets a crafted HTTP Host header bypass path-based authorization. Affects any HTTP/SSE-transport MCP server. Stdio servers are unaffected.
fastmcp_wrapper_layer HIGH Sync @mcp.tool() functions that call asyncio.run(...) inside their body. FastMCP invokes tools inside an already-running event loop; asyncio.run() raises RuntimeError. Looks fine in unit tests, dies on the first real protocol call.
tool_input_validation LOW @mcp.tool() parameters typed as bare str / bytes / Any / list[Any] / dict[..., Any] or with no annotation at all. The schema FastMCP exposes to the LLM is the substrate prompt-injection-via-tool-description attacks rely on; constraining it (Annotated[str, Field(max_length=N)], Literal[...], Pydantic models) closes the window without losing expressiveness. Hygiene check, not a CVE — expect findings even on well-written servers. Added in v0.2.
command_injection HIGH @mcp.tool() functions where a tool parameter (or a local tainted via assignment / .format() / string concat) flows into os.system, os.popen, or subprocess.* with shell=True or a tainted-interpolated command string. v0.4 added same-file cross-function taint propagation: the analyzer now follows local helper calls (positional + keyword binding, recursion-visited guard), so tool -> helper -> sink flows are caught. Cross-file taint remains out of scope. The list-of-args / no-shell pattern is correctly NOT flagged. Added in v0.3, cross-function in v0.4.
destructive_fs_sink MEDIUM @mcp.tool() functions where a tool parameter flows into a destructive filesystem call — shutil.rmtree, os.remove / os.unlink / os.rmdir / os.removedirs, or Path.unlink() / Path.rmdir() — with no path-containment guard, letting a caller delete arbitrary paths the server can reach. Suppressed when the function canonicalizes-and-confines the path (realpath/resolve + startswith/relative_to) or checks it against a server-managed allow-set — a deliberate false-negative bias. Found the unguarded shutil.rmtree(directory) in manim-mcp-server's cleanup_manim_temp_dir that the other four checks all miss. Added in v0.7.

More checks are landing — hard-coded secrets, write-API tools missing a FORBIDDEN_NAMES-style guardrail, read-only-by-default violations (e.g. SQL read-only enforced by keyword prefix rather than a real read-only connection), path traversal in filesystem-touching servers.

Output format

$ mcp-audit examples/bad/
[HIGH  ] starlette_badhost @ uv.lock
           uv lockfile pins starlette==0.36.3 — vulnerable to BadHost (CVE-2026-48710). Patched in 1.0.1.
           -> Upgrade Starlette to >=1.0.1 (the BadHost patch). If FastAPI pulls Starlette transitively, pin it explicitly. ...

[HIGH  ] fastmcp_wrapper_layer @ server.py:18
           tool 'fetch_url' (def) calls asyncio.run() inside its body. FastMCP invokes tools inside an already-running event loop, and asyncio.run() raises RuntimeError when nested. This will fail at the first real MCP protocol call even if every unit test passes.
           -> Convert the tool to `async def` and replace `asyncio.run(...)` with `await`. ...

mcp-audit: 2 finding(s) — 2 high

--json emits one object: {"root": "...", "finding_count": N, "findings": [...]}. Each finding has check, severity, path, line, message, remediation.

What this is not

  • It is not a runtime sandbox. Static analysis only.
  • It does not install your venv to introspect it. It reads what's declared (manifests + lockfiles + source).
  • It will not detect every vulnerability — only the classes its checks know about. Treat zero findings as "no known issues from this tool," not as a clean bill.

Background

Development

git clone https://github.com/Alienbushman/mcpdone-samples
cd mcpdone-samples/mcp-audit
pip install -e ".[dev]"
pytest
python smoke_test.py

To add a check: drop src/mcp_audit/checks/<name>.py exposing a module-level CHECK_ID and a check(root: Path) -> list[Finding] callable. Register it in src/mcp_audit/checks/__init__.py. Add fixtures + tests under tests/.

License

MIT.

Release files for mcpdone-audit 0.7.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for mcpdone-audit 0.7.0
File Size Uploaded
mcpdone_audit-0.7.0.tar.gz 29.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for mcpdone-audit 0.7.0
File Interpreter ABI Platform
mcpdone_audit-0.7.0-py3-none-any.whl Python 3 none any Details

Total release size: 56.3 kB

Release files / mcpdone_audit-0.7.0.tar.gz

Download URL mcpdone_audit-0.7.0.tar.gz
Size 29.5 kB
Tags Source
SHA-256 checksum
How to use checksums
8fcf9e147010d00171f9369c0d84aaa6f948388f8f2830a2fffcb397e5ec6043
BLAKE2b-256 checksum
How to use checksums
3c20d84968251ed18d06072a34cbc92a90ad9394b9858a38808c505c439b6767
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 21, 2026.

Transparency log

Release files / mcpdone_audit-0.7.0-py3-none-any.whl

Download URL mcpdone_audit-0.7.0-py3-none-any.whl
Size 26.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ee6f7df74c854ca80af6b959801744b6f89effcb2bf33fcd36184c0b91e52c8f
BLAKE2b-256 checksum
How to use checksums
e731f5e698dad13162f5d668f5fc61af122c3e0c48af7b90907d007e8f0628a1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 21, 2026.

Transparency log

Release history Release notifications | RSS feed

0.9.0

2 release files

0.8.0

2 release files

This release

0.7.0 This release

2 release files

0.6.0

2 release files

0.5.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page