MCP Config Audit Server (io.github.jmshinhwa/mcp-config-audit)
This MCP server audits a single mcp.json to determine what an agent configuration exposes. The provided description indicates it focuses on configuration details that may reveal sensitive information and operational risks, including inline API keys and unpinned npx launches.
🛠️ Key Features
- Audits one
mcp.json - Identifies what an agent config “gives away,” including inline API keys
- Flags unpinned
npxlaunches
🚀 Use Cases
- Review an MCP agent configuration for exposed secrets
- Check whether
npxusage in the config is pinned
⚡ Developer Benefits
- Provides targeted analysis of configuration contents in
mcp.json - Helps surface security-relevant configuration practices (as described)
⚠️ Limitations
- Scope is limited to auditing a single
mcp.json - No additional capabilities (e.g., tools or outputs) are specified in the provided data