Skip to main content

MCP Server Config Audit

Runs the same checker as the npm package @readystack/mcp-config-audit on a Node.js runtime that pip installs for you (nodejs-wheel-binaries) - no system Node.js needed. Your files are checked locally.

Audit one mcp.json for what an agent config gives away — inline API keys, unpinned npx launches, plaintext remote servers, shell wrappers, auto-approved tools, whole-machine filesystem roots — with line numbers. The shipped sample config _fixtures/dirty.mcp.json (33 lines, five servers) returns 14 findings, 8 of them blocking.

Install

mcp-config-audit file

Node 18+. The same 18 rules as the VS Code extension, from a terminal or CI.

Free

  • Audit one mcp.json against all 18 rules and get every inline credential, unpinned launch and over-broad grant named with its line number and its replacement. The extension ships a sample config, _fixtures/dirty.mcp.json, 33 lines and five servers, which returns 14 findings, 8 of them blocking, and its corrected twin _fixtures/clean.mcp.json, which returns zero.
  • --rules lists every rule

With a licence ($29 once)

  • Audit every agent config in a repository and in the user-scope locations for VS Code, Cursor, Claude Desktop and Windsurf in one pass, fail CI with a non-zero exit code on any blocker, and export a dated evidence report of file, rule and line.
@readystack/mcp-config-audit --dir ./templates --report html --out report.html

Freelance application-security engineers commonly bill $100-$200 an hour; a single review hour costs more than three licences, and the config changes every time somebody adds a server.

Use from an AI agent (MCP)

Claude Code · Cursor · Windsurf · any MCP client - add to your MCP config:

{ "mcpServers": { "mcp-config-audit": { "command": "npx", "args": ["-y", "@readystack/mcp-config-audit", "--mcp"] } } }

Tools: check_text and check_file (free) · check_dir (licence). The agent gets every finding with the line number.

Use in CI

- name: MCP Server Config Audit
  run: npx -y @readystack/mcp-config-audit --dir . --ci

(container: docker run --rm -v "$PWD:/work" getreadystack/mcp-config-audit --dir /work --ci)

The folder sweep, reports and CI mode need one licence — one payment, no subscription. Set READYSTACK_LICENSE=<key> or run --license <key> once.

Get a licence

Install (PyPI)

pip install readystack-mcp-config-audit
mcp-config-audit --help

Release files for readystack-mcp-config-audit 1.0.7.post1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for readystack-mcp-config-audit 1.0.7.post1
File Size Uploaded
readystack_mcp_config_audit-1.0.7.post1.tar.gz 22.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for readystack-mcp-config-audit 1.0.7.post1
File Interpreter ABI Platform
readystack_mcp_config_audit-1.0.7.post1-py3-none-any.whl Python 3 none any Details

Total release size: 46.2 kB

Release files / readystack_mcp_config_audit-1.0.7.post1.tar.gz

Download URL readystack_mcp_config_audit-1.0.7.post1.tar.gz
Size 22.0 kB
Tags Source
SHA-256 checksum
How to use checksums
33af1e1a1f9d569861887ffeb898a8e1231b14cf88468d86debd1c18c52d21d4
BLAKE2b-256 checksum
How to use checksums
df289729446099cd4e9578e6f7a77ddcea46dd96e84c600ab03fb823d1a88e90
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.3

Release files / readystack_mcp_config_audit-1.0.7.post1-py3-none-any.whl

Download URL readystack_mcp_config_audit-1.0.7.post1-py3-none-any.whl
Size 24.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ebe422d019915892f0ce074d6b3dfeca59f953b382321c8ecca092975ea4231d
BLAKE2b-256 checksum
How to use checksums
a22b950f4e2504ab67da22582cf041753cc4ea5777a5648f6e6090e2d4aa0ebb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

1.0.7.post1 This release

2 release files

1.0.6

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page