Releases: catidegla/mcpaudit
Release list
v0.1.1
A GitHub Action
- uses: catidegla/mcpaudit@v0.1.1
with:
path: .
fail-on: high
- uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: mcpaudit.sarifSARIF is written before the exit code is decided, because the annotations on the diff are the useful part and they have to exist even when the scan fails the job.
CI drives the action over both corpora on every commit. The poisoned manifest has to fail it, and the benign corpus has to come back empty at the lowest threshold. The second half is the one that decides whether anybody keeps a scanner installed.
No change to the scanner itself. 37 tests.
v0.1.0
First release. Published as @catidegla/mcpaudit.
A tool description is not documentation. It reaches the model as instructions,
written by whoever published the server, and in most clients nobody reads it
after the first install. This scans MCP servers before you approve them.
- Hidden instructions: Unicode tag characters, bidirectional overrides, zero
width joiners, and other concealment in text the model will read - Tool poisoning and cross server shadowing
- Credentials and unsafe configuration in server manifests
- Findings mapped to the OWASP MCP Top 10, with a confidence score
- Pretty output for a terminal, SARIF for code scanning
Local, no API key, zero dependencies. The flagship test is a false positive
corpus: benign servers that look alarming, which the scanner has to leave alone.