New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@guardbee/mcp-config-auditor

Package Overview
Dependencies
Maintainers
1
Versions
4
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@guardbee/mcp-config-auditor

MCP server that audits installed MCP client configs (Cursor, Claude Desktop, Windsurf, VS Code) and agent SKILL.md files for unpinned packages, secrets, wildcard auto-approve, unauthenticated remote endpoints, typosquats, unrestricted skill tools, and cro

latest
Source
npmnpm
Version
0.3.1
Version published
Maintainers
1
Created
Source

@guardbee/mcp-config-auditor

🇬🇧 English | 🇹🇷 Türkçe

An MCP server that audits the MCP client config on a machine: Cursor mcp.json, Claude Desktop claude_desktop_config.json, Windsurf mcp_config.json, and VS Code mcp.json.

mcp-server-auditor reads an MCP server's source. This package reads the config that decides which servers an agent will run. It does not start those servers and it does not send the config anywhere.

Claude ──► mcp-config-auditor ──► mcp.json
              │
              ├─ Unpinned package     (npx -y pkg, @latest)
              ├─ Typosquat            (one edit from a known server package)
              ├─ Secret in env/args
              ├─ autoApprove "*"
              ├─ Remote HTTP without auth
              ├─ Cross-server shadowing (when you pass a tool inventory)
              └─ Agent SKILL.md (allowed-tools, body, lookalike names)

Checks

PatternSeverityOWASPWhat it means
unpinned_packagehighMCP04:2025A launcher (npx, uvx, pnpm, yarn, bunx, pipx) runs a package with no major.minor.patch pin
typosquat_packagecriticalMCP04:2025The package name is one edit from a known MCP server package
secret_in_envcriticalMCP01:2025A credential-shaped value or a sensitive key with a long literal
secret_in_argscriticalMCP01:2025A token on the command line
auto_approve_wildcardcriticalMCP02:2025autoApprove / alwaysAllow is * or true
cleartext_remotehighMCP07:2025A non-loopback http:// URL
unauthenticated_remotehigh/mediumMCP07:2025A non-loopback URL with no Authorization / API-key header and no token env var
cross_server_tool_shadowhighMCP03:2025The same tool name on two servers
confusable_tool_namecriticalMCP03:2025Homoglyph or one-edit tool names across servers
cross_server_tool_redirecthighMCP03:2025A description tells the model to call another server's tool
skill_unrestricted_shellcriticalMCP02:2025allowed-tools includes bare Bash, shell, or *
skill_unrestricted_writehighMCP02:2025allowed-tools includes Write or Edit with no path limit
skill_instruction_overridecriticalMCP06:2025The skill tells the model to ignore prior instructions
skill_covert_instructioncriticalMCP06:2025The skill tells the model to hide its behavior from the user
skill_secret_file_readcriticalMCP01:2025The skill tells the model to read .ssh, .env, or a similar file
skill_at_secret_refcriticalMCP01:2025An @ reference inlines a credential path
secret_in_skillcriticalMCP01:2025A literal token is written in the skill file
skill_name_shadowhighMCP03:2025Two SKILL.md files use the same name
skill_confusable_namecriticalMCP03:2025Two skill names differ only by a lookalike character

Loopback URLs (localhost, 127.0.0.1, ::1) are not remote findings. Placeholder values (${API_KEY}, changeme) are not secrets. Reported secret matches are redacted. Bash(git diff:*) is a command allowlist and is not an unrestricted shell. Read alone is not flagged.

Quick start

{
  "mcpServers": {
    "guardbee-mcp-config-auditor": {
      "command": "npx",
      "args": ["-y", "@guardbee/mcp-config-auditor"]
    }
  }
}
npx @guardbee/mcp-config-auditor scan .cursor/mcp.json --fail-on=high --format=sarif > results.sarif
npx @guardbee/mcp-config-auditor inventory ./tool-inventory.json

A directory scan opens mcp.json, mcp_config.json, claude_desktop_config.json, and SKILL.md. Pass a file path to scan any other name. A file named SKILL.md is audited as an agent skill. Same-name and lookalike skill findings appear on a directory scan, because one file cannot see the others.

guardbee.yml:

mcp-config-auditor:
  fail-on: high
  max-files: 5000
  exclude:
    - "fixtures/"

Tool inventory shape:

{
  "servers": [
    { "name": "github", "tools": [{ "name": "create_issue", "description": "Open an issue" }] }
  ]
}

Shadowing needs that inventory because a client config does not list tools. rug-pull-detector can collect a live tools/list; this package compares several of those lists.

Keywords

mcp

FAQs

Package last updated on 28 Sep 2026

Related posts