Skip to content

Releases: catidegla/mcpaudit

Release list

v0.1.1

Choose a tag to compare

@catidegla catidegla released this 11 Sep 16:24

A GitHub Action

- uses: catidegla/mcpaudit@v0.1.1
  with:
    path: .
    fail-on: high

- uses: github/codeql-action/upload-sarif@v3
  with:
    sarif_file: mcpaudit.sarif

SARIF is written before the exit code is decided, because the annotations on the diff are the useful part and they have to exist even when the scan fails the job.

CI drives the action over both corpora on every commit. The poisoned manifest has to fail it, and the benign corpus has to come back empty at the lowest threshold. The second half is the one that decides whether anybody keeps a scanner installed.

No change to the scanner itself. 37 tests.

v0.1.0

Choose a tag to compare

@catidegla catidegla released this 08 Sep 14:28

First release. Published as @catidegla/mcpaudit.

A tool description is not documentation. It reaches the model as instructions,
written by whoever published the server, and in most clients nobody reads it
after the first install. This scans MCP servers before you approve them.

  • Hidden instructions: Unicode tag characters, bidirectional overrides, zero
    width joiners, and other concealment in text the model will read
  • Tool poisoning and cross server shadowing
  • Credentials and unsafe configuration in server manifests
  • Findings mapped to the OWASP MCP Top 10, with a confidence score
  • Pretty output for a terminal, SARIF for code scanning

Local, no API key, zero dependencies. The flagship test is a false positive
corpus: benign servers that look alarming, which the scanner has to leave alone.