mcpdone-audit
Last released
Static analyzer for MCP server repos, Python and TypeScript/JavaScript: 10 checks (BadHost / Starlette CVE-2026-48710, FastMCP wrapper-layer asyncio.run bug, loose tool schemas, subprocess command-injection w/ cross-function taint propagation, destructive-filesystem sinks from tool params, keyword-guarded SQL read-only bypass, and a TS engine covering DNS-rebinding-unprotected HTTP transports / CVE-2025-66414, child_process injection, destructive fs sinks, and unconstrained zod tool schemas).