1. Conduid
  2. AI
  3. Audit
MCP server · AI

Audit

mcp-audit — A Go tool for auditing Model Context Protocol (MCP) servers.

Unclaimed last commit a year ago ai
41Fair

Scored 3 months ago · breakdown

About Audit

Audit is an MCP server published by mkokoulin in the AI category: mcp-audit — A Go tool for auditing Model Context Protocol (MCP) servers. It has been installed 0 times through Conduid.

The repository has 3 stars and 0 forks, with the last commit a year ago. Six months or more without a commit doesn't mean the server is broken, but check the open issues (0) before depending on it in production.

Install

Install
npx mcp-audit

This server has no ConduID identity, so agent calls to it are not receipted. Pin the version you install and review the source before granting it credentials.

Ask AI

Ask AI about Audit

Powered by Claude · Grounded in docs

I know everything about Audit. Ask me about installation, configuration, usage, or troubleshooting.

Security checks

  • ·README presentNot checked yet.
  • ·License declaredNot checked yet.
  • ·Tests presentNot checked yet.
  • ·Dependencies pinnedNot checked yet.
  • ·No dynamic code executionNot checked yet.
  • !Scoped permissionsDoesn't declare a permission scope. Assume it can do anything its process can.

README

mcp-audit

mcp-audit — A Go tool for auditing Model Context Protocol (MCP) servers.

Features

  • 🔍 Probe — runs the target MCP server and inspects supported features via JSON-RPC (tools, resources, prompts, sampling, transports).
  • 📝 Scan — statically analyzes TypeScript source code (AST) to detect declared MCP APIs and transport usage.

CLI flags

-cwd is the local path of the project.
-github — GitHub is the URL for auto-cloning.
-args — additional arguments for the server.
-timeout — request timeout.
-startup-delay — delay before initialize.
-env — passing environment variables.
-ProtocolVersion is the version of the MCP protocol.
-out is the report format.

example

  go run ./cmd/mcp-probe \
  -github "https://github.com/upstash/context7" \
  -out json \
  -timeout 90s -startup-delay 2s 

output format

{
  "MCP Protocol Support": {
    "HTTP Transport": true,
    "Logging": false,
    "OAuth2 Auth": false,
    "Prompts": false,
    "Resources": false,
    "Roots": false,
    "SSE Transport": false,
    "STDIO Transport": true,
    "Sampling": false,
    "Tools": false
  }
}

README mirrored from the source repository 3 months ago. The original is authoritative.

Questions

About Audit

How do I install Audit?

Run npx mcp-audit, then add the server to your MCP client's configuration. Conduid has recorded 0 installs, so the command is known to work with current clients.

Is Audit safe to use with an AI agent?

Its trust score is 41 out of 100 (fair). It passes 0 of 1 static security checks; the failures are listed above. It has no ConduID identity yet, so agent calls to it are not receipted.

Is Audit still maintained?

The last commit was a year ago, with 0 open issues. That's long enough that you should check whether the maintainer is responding to issues before depending on it.