github Python re-analysis due

saagpatel/MCPAudit

v2.7.0
github

Audit all locally configured MCP servers for permission risks, prompt injection threats, and schema drift

maintainer
saagpatel
licence
MIT
first seen
2026-06-06
last seen
2026-09-10
releases · 30d
2
short id

saagpatel/MCPAudit is an MCP server distributed on github, maintained by saagpatel, tracked here since June 2026. It has shipped 53 releases (currently 2.7.0) and exposes 13 tools. Tools include check_server, get_artifact_verify_findings, get_escalation_findings, get_high_risk_servers, get_injection_findings, get_integrity_findings, and 7 more. Its composite risk grade is C — an inferred review prompt computed from observed signals, not a verdict.

what we found

Reading the source raised one review prompt — dangerous code — each a pattern worth a human look rather than a finding of fault.

Its 13 tools appear to reach filesystem, shell / exec, network, secrets and database, inferred from tool names, descriptions and input schemas rather than from observed behaviour.

full security breakdown →
tools 13
  • check_server
  • get_artifact_verify_findings
  • get_escalation_findings
  • get_high_risk_servers
  • get_injection_findings
  • get_integrity_findings
  • get_package_verify_findings
  • get_provenance_findings
  • get_shadowing_findings
  • get_ssrf_findings
  • get_trifecta_findings
  • list_discovered_servers
  • scan_mcp_servers
release cadence · 90d 15 releases
06-13 00:00 07-27 00:00 now
recent releases last 10
version date src
v2.7.0 2026-08-16 github
2.7.0 2026-08-16 pypi
2.6.0 2026-08-05 pypi
v2.5.0 2026-07-20 github
2.5.0 2026-07-20 pypi
v2.4.0 2026-07-03 github
2.4.0 2026-07-03 pypi
2.3.0 2026-07-03 pypi
2.2.3 2026-06-28 pypi
2.2.2 2026-06-28 pypi

view all →