Audit all locally configured MCP servers for permission risks, prompt injection threats, and schema drift
saagpatel/MCPAudit is an MCP server distributed on github, maintained by saagpatel, tracked here since June 2026. It has shipped 53 releases (currently 2.7.0) and exposes 13 tools. Tools include check_server, get_artifact_verify_findings, get_escalation_findings, get_high_risk_servers, get_injection_findings, get_integrity_findings, and 7 more. Its composite risk grade is C — an inferred review prompt computed from observed signals, not a verdict.
Reading the source raised one review prompt — dangerous code — each a pattern worth a human look rather than a finding of fault.
full security breakdown →-
check_server -
get_artifact_verify_findings -
get_escalation_findings -
get_high_risk_servers -
get_injection_findings -
get_integrity_findings -
get_package_verify_findings -
get_provenance_findings -
get_shadowing_findings -
get_ssrf_findings -
get_trifecta_findings -
list_discovered_servers -
scan_mcp_servers
06-13 00:00 07-27 00:00 now
| version | date | src |
|---|---|---|
| v2.7.0 | 2026-08-16 | github |
| 2.7.0 | 2026-08-16 | pypi |
| 2.6.0 | 2026-08-05 | pypi |
| v2.5.0 | 2026-07-20 | github |
| 2.5.0 | 2026-07-20 | pypi |
| v2.4.0 | 2026-07-03 | github |
| 2.4.0 | 2026-07-03 | pypi |
| 2.3.0 | 2026-07-03 | pypi |
| 2.2.3 | 2026-06-28 | pypi |
| 2.2.2 | 2026-06-28 | pypi |