🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

mcp-customs

Package Overview
Dependencies
Maintainers
1
Versions
2
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

mcp-customs

Inspect an MCP server for common security risks before you install it. Offline, zero telemetry.

latest
Source
npmnpm
Version
0.1.1
Version published
Maintainers
1
Created
Source

mcp-customs

Inspect an MCP server for common security risks before you install it. Runs fully offline. No telemetry, no cloud upload, no account.

npx mcp-customs scan ./some-mcp-server
──────────────────────────────────────────────────────
MCP-CUSTOMS INSPECTION REPORT
──────────────────────────────────────────────────────
target        ./some-mcp-server
files scanned 14
score         62 / 100
stamp         [ REVIEW ]
──────────────────────────────────────────────────────
[HIGH] MCP002 — Unsanitized file path (possible path traversal)
  server.js:41  return fs.readFileSync(userPath, 'utf8');
  fix: Resolve the path against an allowed base directory ...

Why

Developers install MCP servers the way they used to install npm packages — quickly, trusting the name, and moving on. An MCP server can read your files, call your APIs, and execute commands on your behalf. Almost nobody checks what it can actually do before connecting it to their agent.

mcp-customs is the "audit before install" step, run locally, in seconds.

What it checks (v0.1)

RuleSeverityWhat it looks for
MCP001criticalShell command execution with unsanitized interpolation
MCP002highFile reads/writes without a path-traversal guard
MCP003criticaleval() / dynamic code execution
MCP004highHardcoded API keys / credentials
MCP005criticalTool descriptions containing hidden-instruction language (prompt injection via the tool's own metadata)
MCP006mediumOutbound network calls combined with environment-variable reads (possible exfiltration)
MCP007lowNo permissions/scopes declared in the manifest

These are heuristic, regex-based checks — fast and fully auditable in one sitting, not a dataflow analysis. They will produce false positives and will miss things a deeper analysis would catch. Treat a CLEARED stamp as "nothing obvious," not "verified safe."

CI usage

# .github/workflows/mcp-customs.yml
- run: npx mcp-customs scan . --sarif results.sarif --fail-on high
- uses: github/codeql-action/upload-sarif@v3
  with:
    sarif_file: results.sarif

Get a badge for your README

npx mcp-customs scan . --badge --name your-server-name

Roadmap

  • Publish scan results to a public registry (mcp-customs.dev) with searchable trust scores
  • Dynamic/sandboxed analysis (catch what static checks miss)
  • Python-specific AST checks (current Python rules are regex-only)
  • Community flagging / verification on registry entries

License

Apache-2.0. No open-core trap — this CLI stays free either way. If a hosted registry/dashboard ships later, that's a separate paid product; this tool's local scanning will never require it.

Keywords

mcp

FAQs

Package last updated on 31 Jul 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts