MCP Server Config Audit
Runs the same checker as the npm package
@readystack/mcp-config-auditon a Node.js runtime that pip installs for you (nodejs-wheel-binaries) - no system Node.js needed. Your files are checked locally.
Audit one mcp.json for what an agent config gives away — inline API keys, unpinned npx launches, plaintext remote servers, shell wrappers, auto-approved tools, whole-machine filesystem roots — with line numbers. The shipped sample config _fixtures/dirty.mcp.json (33 lines, five servers) returns 14 findings, 8 of them blocking.
Install
mcp-config-audit file
Node 18+. The same 18 rules as the VS Code extension, from a terminal or CI.
Free
- Audit one mcp.json against all 18 rules and get every inline credential, unpinned launch and over-broad grant named with its line number and its replacement. The extension ships a sample config, _fixtures/dirty.mcp.json, 33 lines and five servers, which returns 14 findings, 8 of them blocking, and its corrected twin _fixtures/clean.mcp.json, which returns zero.
--ruleslists every rule
With a licence ($29 once)
- Audit every agent config in a repository and in the user-scope locations for VS Code, Cursor, Claude Desktop and Windsurf in one pass, fail CI with a non-zero exit code on any blocker, and export a dated evidence report of file, rule and line.
@readystack/mcp-config-audit --dir ./templates --report html --out report.html
Freelance application-security engineers commonly bill $100-$200 an hour; a single review hour costs more than three licences, and the config changes every time somebody adds a server.
Use from an AI agent (MCP)
Claude Code · Cursor · Windsurf · any MCP client - add to your MCP config:
{ "mcpServers": { "mcp-config-audit": { "command": "npx", "args": ["-y", "@readystack/mcp-config-audit", "--mcp"] } } }
Tools: check_text and check_file (free) · check_dir (licence). The agent gets every finding with the line number.
Use in CI
- name: MCP Server Config Audit
run: npx -y @readystack/mcp-config-audit --dir . --ci
(container: docker run --rm -v "$PWD:/work" getreadystack/mcp-config-audit --dir /work --ci)
The folder sweep, reports and CI mode need one licence — one payment, no subscription. Set READYSTACK_LICENSE=<key> or run --license <key> once.
Install (PyPI)
pip install readystack-mcp-config-audit
mcp-config-audit --help
Release files for readystack-mcp-config-audit 1.0.6
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| readystack_mcp_config_audit-1.0.6.tar.gz | 21.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| readystack_mcp_config_audit-1.0.6-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 45.6 kB
Release files / readystack_mcp_config_audit-1.0.6.tar.gz
| Download URL | readystack_mcp_config_audit-1.0.6.tar.gz |
|---|---|
| Size | 21.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
49757a91aa4c2c8edd7245a24987d7098895da7b711b050e7139844899f37a9e
|
|
BLAKE2b-256 checksum How to use checksums |
e641a13edc1097be95c41339f872b84eb9a2f06caed40c21a7442b375afee389
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.3
|
Release files / readystack_mcp_config_audit-1.0.6-py3-none-any.whl
| Download URL | readystack_mcp_config_audit-1.0.6-py3-none-any.whl |
|---|---|
| Size | 23.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b04e2f427ef1f04db824f7c6df09b42e3245f99ae3fffa27c740a566ff7b55ee
|
|
BLAKE2b-256 checksum How to use checksums |
34f4181feeaeb270daedfe80f5a23934d3d48c1bba846ac7582e137b64938e68
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.3
|