Skip to main content

MCP Server Config Audit

Runs the same checker as the npm package @readystack/mcp-config-audit on a Node.js runtime that pip installs for you (nodejs-wheel-binaries) - no system Node.js needed. Your files are checked locally.

Audit one mcp.json for what an agent config gives away — inline API keys, unpinned npx launches, plaintext remote servers, shell wrappers, auto-approved tools, whole-machine filesystem roots — with line numbers. The shipped sample config _fixtures/dirty.mcp.json (33 lines, five servers) returns 14 findings, 8 of them blocking.

Install

mcp-config-audit file

Node 18+. The same 18 rules as the VS Code extension, from a terminal or CI.

Free

  • Audit one mcp.json against all 18 rules and get every inline credential, unpinned launch and over-broad grant named with its line number and its replacement. The extension ships a sample config, _fixtures/dirty.mcp.json, 33 lines and five servers, which returns 14 findings, 8 of them blocking, and its corrected twin _fixtures/clean.mcp.json, which returns zero.
  • --rules lists every rule

With a licence ($29 once)

  • Audit every agent config in a repository and in the user-scope locations for VS Code, Cursor, Claude Desktop and Windsurf in one pass, fail CI with a non-zero exit code on any blocker, and export a dated evidence report of file, rule and line.
@readystack/mcp-config-audit --dir ./templates --report html --out report.html

Freelance application-security engineers commonly bill $100-$200 an hour; a single review hour costs more than three licences, and the config changes every time somebody adds a server.

Use from an AI agent (MCP)

Claude Code · Cursor · Windsurf · any MCP client - add to your MCP config:

{ "mcpServers": { "mcp-config-audit": { "command": "npx", "args": ["-y", "@readystack/mcp-config-audit", "--mcp"] } } }

Tools: check_text and check_file (free) · check_dir (licence). The agent gets every finding with the line number.

Use in CI

- name: MCP Server Config Audit
  run: npx -y @readystack/mcp-config-audit --dir . --ci

(container: docker run --rm -v "$PWD:/work" getreadystack/mcp-config-audit --dir /work --ci)

The folder sweep, reports and CI mode need one licence — one payment, no subscription. Set READYSTACK_LICENSE=<key> or run --license <key> once.

Get a licence

Install (PyPI)

pip install readystack-mcp-config-audit
mcp-config-audit --help

Release files for readystack-mcp-config-audit 1.0.6

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for readystack-mcp-config-audit 1.0.6
File Size Uploaded
readystack_mcp_config_audit-1.0.6.tar.gz 21.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for readystack-mcp-config-audit 1.0.6
File Interpreter ABI Platform
readystack_mcp_config_audit-1.0.6-py3-none-any.whl Python 3 none any Details

Total release size: 45.6 kB

Release files / readystack_mcp_config_audit-1.0.6.tar.gz

Download URL readystack_mcp_config_audit-1.0.6.tar.gz
Size 21.7 kB
Tags Source
SHA-256 checksum
How to use checksums
49757a91aa4c2c8edd7245a24987d7098895da7b711b050e7139844899f37a9e
BLAKE2b-256 checksum
How to use checksums
e641a13edc1097be95c41339f872b84eb9a2f06caed40c21a7442b375afee389
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.3

Release files / readystack_mcp_config_audit-1.0.6-py3-none-any.whl

Download URL readystack_mcp_config_audit-1.0.6-py3-none-any.whl
Size 23.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b04e2f427ef1f04db824f7c6df09b42e3245f99ae3fffa27c740a566ff7b55ee
BLAKE2b-256 checksum
How to use checksums
34f4181feeaeb270daedfe80f5a23934d3d48c1bba846ac7582e137b64938e68
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

1.0.6 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page